hi, We are using samba as a client and running winbindd for authenticating logins to Linux systems. As per https://lists.samba.org/archive/samba-technical/2014-August/101931.html, the change to winbindd_rpc.c states that if the trusted domain has no SID, winbindd just aborts the session. We have seen this happening with MIT Kerberos realm added as trust to AD and winbindd just returns without processing further as there is no SID returned for the Linux system having kerberos support. The request is to handle this. Thanks, Vishwanath
Hello vishwanath, winbind is basically a service for connecting Linux, MAC, Solaris, Other OS to Windows. Now in an Active Directory environment, when new account (user, group, computer) is created, domain controller which holds RID Master (relative identifier) role generates a SID for the new account and writes to Active Directory database. I believe during domain creation sid is allocated. What's your requirement, when handling domain without sid. Do you want winbind not to abort and perform normal lookups with joined domain or something specific?
hi Amit, As you stated, that is the requirement. Winbindd instead of aborting the request, can it process the remaining trusted domain SIDs that it got. Leave out the one not received.
Created attachment 15193 [details] patch for winbind handling NULL sids
Comment on attachment 15193 [details] patch for winbind handling NULL sids Can you please propose this patch as a merge request, so we can see the CI results and potentially merge it? It would be great if we could have a test - presumably we can set up an MIT trust without the other realm actually existing because it doesn't speak any protocols winbindd knows anyway. That would be the best way to prevent a regression. https://wiki.samba.org/index.php/Samba_CI_on_gitlab#Creating_a_merge_request
@Andrew Bartlett, you had commented before as follows: winbindd: Do not segfault if the trusted domain has no SID Currently we abort, as skipping the domain would make the loop much more complex for a situation not yet seen in the real world. https://github.com/samba-team/samba/commit/a348959088348560fe31fdc73b8482214c4021bf Just wanted to make sure this patch wont be missing anything needed.