Displaying 1 result from an estimated 1 matches for "agdlp".
Did you mean:
adlp
2014 Mar 27
0
AD DC, winbind and Domain Local type groups
...added and removed?
EXAMPLE+FileAcc-Common:*:4000000:
Below is some tests. My conclusion is that groups of scope Domain Local
is not found and enumerated by winbind. Nor is any of type Distribution.
This will be a problem in an environment with trusts or just following
Microsofts recommendation AGDLP ("account, global, domain local,
permission"). See http://en.wikipedia.org/wiki/AGDLP for a quick
explanation.
Regards
Davor Vusir
---
/usr/local/samba/bin/samba-tool group add SambaTool-DL-Sec
--group-scope=Domain|Global|Universal --group-type=Security|Distribution
root at dc1:~#...