Samba PDC + ACL - howto map users and groups on windows clients
I'm trying to setup ACL on my network but samba is being a big problem to me.
Well, all the unix machines are working very well with nfs + acl but the windows machines doesn't saw the unix users/groups, so the windows users can't access the acl exported share.
I'm using gentoo with samba 3.0.22-r3 with acl, kerberos and wibind support and I did tried several parameters combination on smb.conf like the follow:
domain master = yes
preferred master = yes
local master = yes
domain logons = yes
os level = 65
security = ADS
idmap uid = 500-10000000
idmap gid = 500-10000000
winbind enum users = yes
winbind enum groups = yes
inbind use default domain = Yes
nt acl support = yes
winbind nested groups = Yes
in any setup try I can't map the users on windows machine.
Looking at google I'd read about wbinfo and now I can think that there's some problem/mistake with my setup since even if I run winbindd I can't get any user/groups info:
web03 myers # wbinfo -u
Error looking up domain users
web03 myers # wbinfo -g
Error looking up domain groups
but I can get some domain informations:
web03 myers # wbinfo -D DOMAINAME
Name : DOMAINAME
SID : S-1-5-21-1020034761-3042356540-2715085242
Active Directory : No
Native : No
Primary : Yes
Sequence : -1
also, if I try to join the domain:
web03 shares # net ads join DOMAINNAME
[2006/09/04 17:10:52, 0] utils/net_ads.c:ads_startup(191)
ads_connect: Transport endpoint is not connected
and if I try to run kinit:
web03 shares # kinit Administrator@DOMAINAME
kinit(v5): Cannot resolve network address for KDC in requested realm while getting initial credentials
Well, that's my only server machine for windows, all windows machines are just clients who log in on samba domain with the password mapped on smbpasswd file and this configuration is working very well, my only problem is with acl support on windows side.
What may I doing wrong? or acl support just work with a real windows ads controller using winbind to map from windows to unix? what I need is the opposite, mapping from unix to windows.
Thanks for any help and sorry for my poor english,