Bluehost.com Web Hosting $6.95

[Samba] wbinfo -u lists ADS users without domain,getent passwd returns only local users

This is a discussion on [Samba] wbinfo -u lists ADS users without domain,getent passwd returns only local users within the Samba forums, part of the Networking and Network Related category; I'm using Samba/Winbind for single-sign on in a network where Active Directory is the authoritative authentication source. ...


Go Back   Usenet Forums > Networking and Network Related > Samba

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 06-03-2008
Thomas Leavitt
 
Posts: n/a
Default [Samba] wbinfo -u lists ADS users without domain,getent passwd returns only local users

I'm using Samba/Winbind for single-sign on in a network where Active
Directory is the authoritative authentication source. The active
directory server is Windows 2003 with Services for Unix installed so
that the schema is extended and the management interface has a "Unix
Attributes" tab.



wbinfo -u produces a list of users, without a DOMAIN+ prefix.



getent passwd lists only local users



although



getent passwd username produces the proper info. Same behavior for
groups.



Could SELinux interference be the problem? This happens even after I
completely disable it, leave the domain, and then rejoin the domain and
restart everything.



Everything is "working", but this strikes me as incorrect behavior.



Here's a dump of my samba config



[global]

workgroup = BLAH

realm = BLAHHQ.BLAH-INC.COM

server string = Samba Server Version %v

security = ADS

auth methods = winbind

password server = BLAH-DC-02.BLAHHQ.BLAH-INC.COM
BLAH-DC-04.BLAHHQ.BLAH-INC.COM

idmap domains = BLAHHQ.BLAH-INC.COM

idmap uid = 16777216-33554431

idmap gid = 16777216-33554431

template homedir = /home/%U

template shell = /bin/bash

winbind separator = +

winbind enum users = Yes

winbind enum groups = Yes

winbind use default domain = Yes

winbind nss info = sfu

idmap config BLAHHQ.BLAH-INC.COM:range = 10000-40000

idmap config BLAHHQ.BLAH-INC.COM:backend = ad

idmap config BLAHHQ.BLAH-INC.COM:default = yes

idmap config BLAHHQ.BLAH-INC.COM:schema_mode = sfu



[homes]

comment = Home Directories

valid users = BLAHHQ.BLAH-INC.COM+%S

read only = No

browseable = No



nsswitch.conf lists "files winbind"



There's nothing particularly exotic going on here, as far as I can tell
(other than the hassle created by SELinux). What am I missing? If y'all
need more info, please tell me.



Regards,

Thomas Leavitt

--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/listinfo/samba

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 01:26 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0