I configured Samba with AD through winbind with *. tdb, but I want to configure samba directly against ldap DP or need to mount a openldap. Is it possible? I want to remove *. tdb. Directly RedHat support: Correcting the permissions on such files and directories can be a very difficult task, requiring significant manual effort, or advanced scripting skills and good backups of the previous idmap. It is for this reason that the tdb default idmap backend is not recommended to be used, especially on any Samba server in which domain users will create files or directories on the filesystem based upon their winbind-enumerated UID and GID numbers. RECOMMENDATION For best results and the least amount of effort required to correct a corrupt idmap TDB file situation, it is highly recommended that the ldap idmap backend be configured for winbind instead. http://kbase.redhat.com/faq/FAQ_71_11158.shtm Esteban Torres Rodr?guez ?REA DE SOPORTE T?CNICO - Administraci?n de Servidores Subdirecci?n de Sistemas Inform?ticos Empresa P?blica Desarrollo Agrario y Pesquero, email: etorres@dap.es