Displaying 6 results from an estimated 6 matches for "gfass".
Did you mean:
gass
2017 Oct 10
2
Domain member server: user access
...figure out things on the shell, digging for
the group on both servers via getent and wbinfo.
Until here there was no decision for a uidNumber or gidNumber.
He did not set one via RSAT. Does he have to do that?
I then deleted the group via samba-tool and created it again:
samba-tool group create gfass --nis-domain=arbeitsgruppe --gid-number=10580
If this is wrong, I am happy to learn how to do that correctly.
I understand that running
wbinfo --group-info="gfass"
is problematic as long as the reported bug isn't fixed, correct?
thanks, Stefan
2017 Oct 09
2
Domain member server: user access
...#39;s still there on the DC:
# wbinfo --group-info="domain admins"
ARBEITSGRUPPE\domain admins:x:3000013:
# net cache flush
# wbinfo --group-info="domain admins"
ARBEITSGRUPPE\domain admins:x:10512:
The new and needed group for the particular ACL:
# wbinfo --group-info="gfass"
ARBEITSGRUPPE\gfass:x:10580:
I chose 10850 just to make sure I am away from other IDs.
Is there a simple way to read the (highest) used group-id?
btw: ACLs work now for the specific folders/ groups, that is not the
problem.
>> Your reported bug still sits there unnoticed, right?
&g...
2017 Oct 09
2
Domain member server: user access
Am 2017-09-26 um 16:16 schrieb Rowland Penny via samba:
> Very simple Stefan, there is a bug and a simple workaround, never (not
> ever) run 'wbinfo -G 100' on a DC if you have given Domain Users a
> gidNumber ;-)
hit the same issue with a domain group today (DC and DM w/ samba-4.6.8)
Solution:
net cache flush, recreate the group via samba-tool, and --gid-number
before that
2017 Oct 09
2
Domain member server: user access
Am 2017-10-09 um 21:04 schrieb Rowland Penny via samba:
> It isn't supposed to work like this and it didn't used to work like
> this.
Then the software shouldn't allow me to do so and/or give useful
feedback, don't you agree?
> I have added this info to the bug report
thanks
2017 Oct 10
0
Domain member server: user access
...butes, you will also be able to use the other RFC2307
attributes.
Whichever winbind backend you use on the Unix domain members, you will
also have to set up the libnss_winbind links.
>
>
> I then deleted the group via samba-tool and created it again:
>
> samba-tool group create gfass --nis-domain=arbeitsgruppe
> --gid-number=10580
>
> If this is wrong, I am happy to learn how to do that correctly.
>
> I understand that running
>
> wbinfo --group-info="gfass"
>
> is problematic as long as the reported bug isn't fixed, correct?
It see...
2017 Oct 10
4
Domain member server: user access
..._winbind links.
OK, I think I understand.
We use backend "ad" on the DM and the DM has
/usr/lib64/libnss_winbind.so* and
# grep winbind /etc/nsswitch.conf
passwd: compat winbind
group: compat winbind
This is what you point me at, right?
>> wbinfo --group-info="gfass"
>>
>> is problematic as long as the reported bug isn't fixed, correct?
>
> It seems to be, but only on a DC, unless you can prove otherwise ;-)
I won't touch things for now ;-)
thanks, Stefan