Welcome to Soft32 Linux Forums!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

[Samba] group mappings pitfalls in samba 3

 
   Soft32 Home -> Linux -> Samba RSS
Next:  [Samba] Samba on SOlaris and Linux Redhat  
Author Message
Andrew Gaffney

External


Since: Nov 20, 2003
Posts: 36



(Msg. 1) Posted: Tue Dec 09, 2003 11:30 am
Post subject: [Samba] group mappings pitfalls in samba 3
Archived from groups: linux>samba (more info?)

I have recently run across this problem and would like to warn people about it. I had an
already established domain running under Samba 2.2.8. I then upgraded to 3.0. I removed
the 'domain admin users = root' line from my smb.conf because certain tools complained
about it being there. After the upgrade, I followed the Samba 3 HOWTO docs on samba.org. I
created my domadm, domguests, and domusers groups. I used the command 'net groupmap add
ntgroup="Domain Admins" UNIXgroup=domadm' to map the groups together. This should have had
the same effect as having the 'domain admin users = root' line in 2.2.8, but whenever I
would logon to any computer in the domain with the user 'root', the user would be a
regular restricted user. I got output like this from 'net groupmap list':

System Operators (S-1-5-32-549) -> -1
Dispatch (S-1-5-21-124999916-2847287174-2328787173-1831) -> dispatch
Replicators (S-1-5-32-552) -> -1
Guests (S-1-5-32-546) -> -1
Domain Users (S-1-5-21-124999916-2847287174-2328787173-1833) -> domusers
Domain Admins (S-1-5-21-124999916-2847287174-2328787173-1825) -> domadm
Domain Guests (S-1-5-21-124999916-2847287174-2328787173-1835) -> domguests
Mechanics (S-1-5-21-124999916-2847287174-2328787173-1827) -> mech
Instructors (S-1-5-21-124999916-2847287174-2328787173-1837) -> instructors
Accounting (S-1-5-21-124999916-2847287174-2328787173-1829) -> accounting
Domain Admins (S-1-5-21-124999916-2847287174-2328787173-512) -> -1
Domain Guests (S-1-5-21-124999916-2847287174-2328787173-514) -> -1
Domain Users (S-1-5-21-124999916-2847287174-2328787173-513) -> -1
Power Users (S-1-5-32-547) -> -1
Print Operators (S-1-5-32-550) -> -1
Administrators (S-1-5-32-544) -> -1
Account Operators (S-1-5-32-548) -> -1
Backup Operators (S-1-5-32-551) -> -1
Users (S-1-5-32-545) -> -1

Apparently, the default groups already existed, but were not used in the mapping. Instead,
new groups with the same name (but not the same GID) were created and mapped. So, my user
was in the Domain Admins group but not THE Domain Admins group. I'm not quite sure if this
is a flaw in the HOWTO or if this only happens when upgrading from 2.2.x. I was able to
fix this problem by deleting the group mappings and remapping with 'net groupmap modify
ntgroup="Domain Admins" UNIXgroup=domadm'. I just made these changes, but I am not on site
to test if they worked, but I have a hunch that they did.

--
Andrew Gaffney

--
To unsubscribe from this list go to the following URL and read the
instructions: http://lists.samba.org/mailman/listinfo/samba
Back to top
Login to vote
Display posts from previous:   
Related Topics:
[Samba] problems with group mappings with ldap - the weirdness continues net groupmap modify ntgroup="Domain Admins" unixgroup="ntadmin" NT Group ...

[Samba] User Data / Profiles / Permission / Mappings Loss .. - We have completed a migration from one Samba server to another Samba. The versions and binaries are exactly the same...

[Samba] Upgrading 2.2.8 -> 3.0 howto, pitfalls? - We have two production servers running Samba 2.2.8 on Redhat 7.x using XFS filesystem with ACL and quota support...

[Samba] Samba 3.0.1pre3/ldap - Strange gid mappings server.. - Good day, I'm running some tests with Samba 3.0.1pre3 with an LDAP sam. LDAP has been, to the best of my abilities,..

[Samba] Samba, Samba PDC and slow XP if user not in admin .. - Like many I ran into the slow winXP client when attached to a samba server. Access times were extremely slow and..

[Samba] Samba 3.0 PDC and Group Listing on Samba Winbind Box - Hello there all. I setup a Samba 3.0 PDC using smbpasswd for authentication on a Mandrake 9.1 system. (I will be..
       Soft32 Home -> Linux -> Samba All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Categories:
 Windows
  Linux
 Mac
 PDA


[ Contact us | Terms of Service/Privacy Policy ]