I have a test setup of samba 4.1.6 under ubuntu 14.04. When I do the query shown at https://wiki.samba.org/index.php/Using_RFC2307_on_a_Samba_DC#Check_if_NIS_Extensions_are_installed_in_your_Directory it shows I have the ypServ30 container installed. If I change this query to -s sub then I find 3 entries in that subtree (see [1] below) However the full schema in /usr/share/samba/setup/ypServ30.ldif has 55 entries. The three records I have correspond to just the last three entries in this file. Questions: - Is this normal for an out-of-the-box Samba install? - Should I install the other 52 LDAP entries, if I want to do centralised user/group mapping for Unix servers? Thanks, Brian. [1] root at dc1:~# ldbsearch -H /var/lib/samba/private/sam.ldb -s sub -b CN=ypservers,CN=ypServ30,CN=RpcServices,CN=System,DC=adtest,DC=int,DC=example,DC=net # record 1 dn: CN=bydefaults,CN=ypservers,CN=ypServ30,CN=RpcServices,CN=System,DC=adtest,DC=int,DC=example,DC=net objectClass: top objectClass: msSFU30NISMapConfig cn: bydefaults instanceType: 4 whenCreated: 20140618075513.0Z whenChanged: 20140618075513.0Z uSNCreated: 3767 uSNChanged: 3767 showInAdvancedViewOnly: TRUE name: bydefaults objectGUID: ac691710-e588-403f-93ed-6840fad3d7de objectCategory: CN=msSFU-30-NIS-Map-Config,CN=Schema,CN=Configuration,DC=adtes t,DC=int,DC=example,DC=net msSFU30KeyAttributes: msSFU30Name msSFU30FieldSeparator:: IA=msSFU30IntraFieldSeparator:: IA=msSFU30SearchAttributes: msSFU30Name msSFU30ResultAttributes: msSFU30Name msSFU30MapFilter: (objectCategory=msSFU30YpServers) distinguishedName: CN=bydefaults,CN=ypservers,CN=ypServ30,CN=RpcServices,CN=Sy stem,DC=adtest,DC=int,DC=example,DC=net # record 2 dn: CN=adtest,CN=ypservers,CN=ypServ30,CN=RpcServices,CN=System,DC=adtest,DC=int,DC=example,DC=net objectClass: top objectClass: msSFU30DomainInfo cn: adtest instanceType: 4 whenCreated: 20140618075513.0Z whenChanged: 20140618075513.0Z uSNCreated: 3768 uSNChanged: 3768 showInAdvancedViewOnly: TRUE name: adtest objectGUID: 78a19690-7641-4355-a92c-3545897c4403 objectCategory: CN=msSFU-30-Domain-Info,CN=Schema,CN=Configuration,DC=adtest,D C=int,DC=example,DC=net msSFU30MasterServerName: DC1 msSFU30OrderNumber: 10000 msSFU30Domains: adtest distinguishedName: CN=adtest,CN=ypservers,CN=ypServ30,CN=RpcServices,CN=System ,DC=adtest,DC=int,DC=example,DC=net # record 3 dn: CN=ypservers,CN=ypServ30,CN=RpcServices,CN=System,DC=adtest,DC=int,DC=example,DC=net objectClass: top objectClass: container cn: ypservers instanceType: 4 whenCreated: 20140618075513.0Z whenChanged: 20140618075513.0Z uSNCreated: 3766 uSNChanged: 3766 showInAdvancedViewOnly: TRUE name: ypservers objectGUID: b116fa4c-ff35-42ca-98ad-72a619c4f43b objectCategory: CN=Container,CN=Schema,CN=Configuration,DC=adtest,DC=int,DC=ex ample,DC=net distinguishedName: CN=ypservers,CN=ypServ30,CN=RpcServices,CN=System,DC=adtest ,DC=int,DC=example,DC=net # returned 3 records # 3 entries # 0 referrals
On 23/06/14 14:28, Brian Candler wrote:> I have a test setup of samba 4.1.6 under ubuntu 14.04. > > When I do the query shown at > https://wiki.samba.org/index.php/Using_RFC2307_on_a_Samba_DC#Check_if_NIS_Extensions_are_installed_in_your_Directory > > it shows I have the ypServ30 container installed. > > If I change this query to -s sub then I find 3 entries in that subtree > (see [1] below) > > However the full schema in /usr/share/samba/setup/ypServ30.ldif has 55 > entries. The three records I have correspond to just the last three > entries in this file. > > Questions: > - Is this normal for an out-of-the-box Samba install? > - Should I install the other 52 LDAP entries, if I want to do > centralised user/group mapping for Unix servers? > > Thanks, > > Brian. > > [1] > root at dc1:~# ldbsearch -H /var/lib/samba/private/sam.ldb -s sub -b > CN=ypservers,CN=ypServ30,CN=RpcServices,CN=System,DC=adtest,DC=int,DC=example,DC=net > > # record 1 > dn: > CN=bydefaults,CN=ypservers,CN=ypServ30,CN=RpcServices,CN=System,DC=adtest,DC=int,DC=example,DC=net > objectClass: top > objectClass: msSFU30NISMapConfig > cn: bydefaults > instanceType: 4 > whenCreated: 20140618075513.0Z > whenChanged: 20140618075513.0Z > uSNCreated: 3767 > uSNChanged: 3767 > showInAdvancedViewOnly: TRUE > name: bydefaults > objectGUID: ac691710-e588-403f-93ed-6840fad3d7de > objectCategory: > CN=msSFU-30-NIS-Map-Config,CN=Schema,CN=Configuration,DC=adtes > t,DC=int,DC=example,DC=net > msSFU30KeyAttributes: msSFU30Name > msSFU30FieldSeparator:: IA=> msSFU30IntraFieldSeparator:: IA=> msSFU30SearchAttributes: msSFU30Name > msSFU30ResultAttributes: msSFU30Name > msSFU30MapFilter: (objectCategory=msSFU30YpServers) > distinguishedName: > CN=bydefaults,CN=ypservers,CN=ypServ30,CN=RpcServices,CN=Sy > stem,DC=adtest,DC=int,DC=example,DC=net > > # record 2 > dn: > CN=adtest,CN=ypservers,CN=ypServ30,CN=RpcServices,CN=System,DC=adtest,DC=int,DC=example,DC=net > objectClass: top > objectClass: msSFU30DomainInfo > cn: adtest > instanceType: 4 > whenCreated: 20140618075513.0Z > whenChanged: 20140618075513.0Z > uSNCreated: 3768 > uSNChanged: 3768 > showInAdvancedViewOnly: TRUE > name: adtest > objectGUID: 78a19690-7641-4355-a92c-3545897c4403 > objectCategory: > CN=msSFU-30-Domain-Info,CN=Schema,CN=Configuration,DC=adtest,D > C=int,DC=example,DC=net > msSFU30MasterServerName: DC1 > msSFU30OrderNumber: 10000 > msSFU30Domains: adtest > distinguishedName: > CN=adtest,CN=ypservers,CN=ypServ30,CN=RpcServices,CN=System > ,DC=adtest,DC=int,DC=example,DC=net > > # record 3 > dn: > CN=ypservers,CN=ypServ30,CN=RpcServices,CN=System,DC=adtest,DC=int,DC=example,DC=net > objectClass: top > objectClass: container > cn: ypservers > instanceType: 4 > whenCreated: 20140618075513.0Z > whenChanged: 20140618075513.0Z > uSNCreated: 3766 > uSNChanged: 3766 > showInAdvancedViewOnly: TRUE > name: ypservers > objectGUID: b116fa4c-ff35-42ca-98ad-72a619c4f43b > objectCategory: > CN=Container,CN=Schema,CN=Configuration,DC=adtest,DC=int,DC=ex > ample,DC=net > distinguishedName: > CN=ypservers,CN=ypServ30,CN=RpcServices,CN=System,DC=adtest > ,DC=int,DC=example,DC=net > > # returned 3 records > # 3 entries > # 0 referrals >Try removing the first part of the base 'CN=ypservers' Rowland
Reasonably Related Threads
- winbind: homeDirectory being ignored
- FW: Followup Restricting to a subset of the domain controllers on a site
- Samba SSSD authentication via userPrincipalName does not work because samba claims that the username does not exist.
- WERR_BAD_NET_RESP on replication
- 4.4.3 on CentOS 6: no guest login