Bug 862195

Summary: authconfig needs to be updated to reflect the samba idmap changes since Samba 3.6
Product: Red Hat Enterprise Linux 6 Reporter: Tomas Mraz <tmraz>
Component: authconfigAssignee: Tomas Mraz <tmraz>
Status: CLOSED ERRATA QA Contact: Iveta Wiedermann <isenfeld>
Severity: high Docs Contact:
Priority: medium    
Version: 6.4CC: asn, gdeschner, isenfeld, sbose
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Fixed In Version: authconfig-6.1.12-11.el6 Doc Type: Bug Fix
Doc Text:
Cause: The new samba-3.6 release changed the way the idmap range for mapping users from the windows active directory to the system uids and gids. Consequence: Authconfig was no longer properly configuring the idmap range in smb.conf when --smbidmapuid and --smbidmapgid options were used. Fix: Authconfig was improved to properly use the new syntax of the idmap range configuration that is supported in samba 3.6. Result: The idmap range is properly configured if authconfig is used.
Story Points: ---
Clone Of: 850824 Environment:
Last Closed: 2013-02-21 11:02:28 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On:    
Bug Blocks: 801095    

Description Tomas Mraz 2012-10-02 09:11:16 UTC
+++ This bug was initially created as a clone of Bug #850824 +++

Description of problem:

In Samba 3.6 the id mapping configuration has been changed and simplified. See the release notes:


and the smb.conf and idmap manpages.

        workgroup = LEVEL1
        realm = LEVEL1.DISCWORLD.SITE
        security = ads

        # v3.6 common id range
        passdb backend = tdbsam
        idmap config * : range = 1000000-1999999

        # Winbind domain idmap
        idmap config LEVEL1 : backend = rid
        idmap config LEVEL1 : range = 100000000-199999999

--- Additional comment from asn@redhat.com on 2012-08-22 15:38:57 CEST ---

The same applies to RHEL 6.4, RHEL 7.0 and Fedora. Should I open a bug for each or will you just clone this bug?

--- Additional comment from tmraz@redhat.com on 2012-08-27 16:55:35 CEST ---

Is the new samba completely backwards incompatible with the old settings?

--- Additional comment from asn@redhat.com on 2012-08-27 17:25:27 CEST ---

No, the old idmap settings will not work anymore. You NEED to change them!

Comment 6 errata-xmlrpc 2013-02-21 11:02:28 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.