Bug 12618 - Winbind on a DC doesn't show a 'ID_TYPE_BOTH' as a user by name.
Winbind on a DC doesn't show a 'ID_TYPE_BOTH' as a user by name.
Status: NEW
Product: Samba 4.1 and newer
Classification: Unclassified
Component: Winbind
4.6.0
All All
: P5 normal
: ---
Assigned To: Samba QA Contact
Samba QA Contact
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-03-09 12:11 UTC by Rowland Penny
Modified: 2017-03-09 12:11 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Rowland Penny 2017-03-09 12:11:19 UTC
It would seem that whilst a group such as Domain Admins is mapped to 'ID_TYPE_BOTH' in idmap.ldb, the OS will only accept the group as a user by number, not by name.

i.e. 'chown Domain\ Admins:Domain\ Admins file.txt' will fail, but 'chown 3000013:Domain\ Admins file.txt' will succeed.

Note that '3000013' is the GID for Domain Admins:

getent group Domain\ Admins
SAMDOM\domain admins:x:3000013:SAMDOM\administrator,SAMDOM\rowland