Bug 180 - winbindd can fail to discern whether SIDs are for users or groups
winbindd can fail to discern whether SIDs are for users or groups
Status: CLOSED FIXED
Product: Samba 3.0
Classification: Unclassified
Component: winbind
3.0.0preX
All other
: P3 critical
: none
Assigned To: Andrew Bartlett
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2003-06-20 17:49 UTC by Marc Kaplan
Modified: 2005-11-14 09:24 UTC (History)
3 users (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marc Kaplan 2003-06-20 17:49:43 UTC
I've seen this on two different customer systems.




Here is what is pinted to the log.winbindd:




entry_index = 26, num_entries = 47


could not look up gid for group DocBaseAdmin


entry_index = 27, num_entries = 47


could not look up gid for group EH_S_Admin


entry_index = 28, num_entries = 47


could not look up gid for group Business


entry_index = 29, num_entries = 47


could not look up gid for group Clinical


entry_index = 30, num_entries = 47


could not look up gid for group RRC_Admin


entry_index = 31, num_entries = 47


could not look up gid for group Cellbio_Admin


entry_index = 32, num_entries = 47


could not look up gid for group Clinical_Admin




wbinfo -g actually shows these groups:


RENOVIS\RRC_Admin


RENOVIS\DocBaseAdmin


RENOVIS\Business


RENOVIS\EH_S_Admin


RENOVIS\Cellbio_Admin


RENOVIS\Clinical_Admin


RENOVIS\Clinical




So we are able enumerate the groups, we're just don't have a record of their GID 
(because we actually have this SID as a user).




What I have done in the past to "fix" this problem is to edit the customer's .
tdb files with tdbtool so that their groups will be recognized.
Comment 1 Gerald (Jerry) Carter 2003-08-15 00:09:00 UTC
If the domain is in a certain state (unknown to me), winbindd 
can fail to discern whether SIDs are for users or groups, and 
makes a guess. If it guesses incorrectly, some users/groups will 
be imported incorrectly into  winbindd_idmap.tdb (e.g. setting a 
User SID with a GID label in the tdb)
Comment 2 Gerald (Jerry) Carter 2003-08-28 09:16:42 UTC
This was logged against beta1 and has no real activity 
in 2 months.  Is this still a bug?  If there is no more
information posted in the next week, I'm going to close 
it out due to lack of information.

(btw....I have no idea what my comment on 8/15 means)
Comment 3 Gerald (Jerry) Carter 2003-10-01 09:39:43 UTC
no more comments, no acticity....
Comment 4 Gerald (Jerry) Carter 2005-02-07 08:39:14 UTC
originally reported against 3.0.0beta1.  CLeaning out 
non-production release versions.
Comment 5 Gerald (Jerry) Carter 2005-08-24 10:21:19 UTC
sorry for the same, cleaning up the database to prevent unecessary reopens of bugs.
Comment 6 Gerald (Jerry) Carter 2005-11-14 09:24:44 UTC
database cleanup