Hi folks, I wonder if anyone can tell me how I do this. We currently have samba-3.0.20b controlling access to several unix file shares on our National domain. This is using winbind and kerberos to authenticate the users to the National DCs. All works really well, having migrated from samba 2 we can now dispense with having to create accounts on the unix boxes as winbind is using an AD group to control access. Problem is, we now need to allow access to users in our International domain also. I've tried : 1) Adding an extra national security group to shares.conf . This group is a universal group so I've added in a user account on international. Doesn't work, winbind is unable to resolve the SID of the user (not suprising I suppose). 2) Adding in a International group in shares.conf . This fails I think because winbind can't look up the user on the International DC . Winbind Log says "auth/auth_util.c:make_server_info_info3(1173) make_server_info_info3: pdb_init_sam failed! " . Many thanks in eager anticipation ! Martin. http://www.bbc.co.uk/ This e-mail (and any attachments) is confidential and may contain personal views which are not the views of the BBC unless specifically stated. If you have received it in error, please delete it from your system. Do not use, copy or disclose the information in any way nor act in reliance on it and notify the sender immediately. Please note that the BBC monitors e-mails sent or received. Further communication will signify your consent to this.