I configure samba on aix 5.3 to use the cif service file from windows client in a active directory architecture.
I install all the opt-samba-base composants (pware.base.22.214.171.124.bff, pware.BerkeleyDB.4.4-NC.126.96.36.199.bff, pware.cyrus-sasl.188.8.131.52.bff, pware.gcc-shared-libs.184.108.40.206.bff, pware.libiconv.220.127.116.11.bff, pware.openssl.0.9.8.3.bff, pware.openldap.18.104.22.168.bff) from samba site.
I compile samba with ad support, configure the smb.conf file with "security = ads" amongst other things.
All fine, i can use share on the aix server and restric the security to groups defined from the active directory windows domain controler.
But when a name group (local or global group) used enderscore caracteren, i can't access to the share.
I defined two same group except the name that use enderscore caractere (ex : test_gr) for one and on no enderscore caractere for the other one (ex : testgr). I have this section on the smb.conf :
comment = test
path = /tmp/samba/test_gr
valid users = @"RESSOURCES+test_gr"
comment = test
path = /tmp/samba/testgr
valid group = @"RESSOURCES+testgr"
(RESSOURCES is the domain name, the windbind separator is defined whith option "winbind separator = +").
It's ok for access to the share testgr but not for the test_gr.
Perhaps a bug ?
*** Bug 4776 has been marked as a duplicate of this bug. ***
sorry for the late response. I just verified that this is not a problem with current samba releases with AIX 7.