Bug 10979 - "winbind use default domain = yes" not working with "force user = username"
Summary: "winbind use default domain = yes" not working with "force user = username"
Alias: None
Product: Samba 3.6
Classification: Unclassified
Component: Winbind (show other bugs)
Version: 3.6.23
Hardware: All Linux
: P5 normal
Target Milestone: ---
Assignee: Michael Adam
QA Contact: Samba QA Contact
Depends on:
Reported: 2014-12-02 21:56 UTC by Ruslan Sivak
Modified: 2014-12-03 12:52 UTC (History)
0 users

See Also:


Note You need to log in before you can comment on or make changes to this bug.
Description Ruslan Sivak 2014-12-02 21:56:26 UTC
After upgrading from 3.6.9 to 3.6.23 and using 

"winbind use default domain = yes" 


"force user = username"

I get the following error:

"The security ID structure is invalid." 

when trying to access the share. 

I found a work around of commenting out the winbind use default domain line and setting 

force user = DOMAIN+username

This works, but has the unfortunate side effects of file listings being owned by DOMAIN+username instead of just username, and users must now login using DOMAIN+username instead of username.  

Hopefully this regression can be fixed.
Comment 1 Volker Lendecke 2014-12-03 07:32:14 UTC

Sorry, but this won't be fixed in 3.6. If you can reproduce in 4.1, please re-open. 3.6 is security fixes only mode now.

Comment 2 Ruslan Sivak 2014-12-03 12:52:29 UTC
How do I get rpms for 4.1 in CentOS 6?  Latest in the repo are 4.0 RC4