Bug 862195 - authconfig needs to be updated to reflect the samba idmap changes since Samba 3.6
authconfig needs to be updated to reflect the samba idmap changes since Samba...
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: authconfig (Show other bugs)
6.4
Unspecified Unspecified
medium Severity high
: rc
: ---
Assigned To: Tomas Mraz
Iveta Wiedermann
:
Depends On:
Blocks: 801095
  Show dependency treegraph
 
Reported: 2012-10-02 05:11 EDT by Tomas Mraz
Modified: 2013-02-21 06:02 EST (History)
4 users (show)

See Also:
Fixed In Version: authconfig-6.1.12-11.el6
Doc Type: Bug Fix
Doc Text:
Cause: The new samba-3.6 release changed the way the idmap range for mapping users from the windows active directory to the system uids and gids. Consequence: Authconfig was no longer properly configuring the idmap range in smb.conf when --smbidmapuid and --smbidmapgid options were used. Fix: Authconfig was improved to properly use the new syntax of the idmap range configuration that is supported in samba 3.6. Result: The idmap range is properly configured if authconfig is used.
Story Points: ---
Clone Of: 850824
Environment:
Last Closed: 2013-02-21 06:02:28 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Tomas Mraz 2012-10-02 05:11:16 EDT
+++ This bug was initially created as a clone of Bug #850824 +++

Description of problem:

In Samba 3.6 the id mapping configuration has been changed and simplified. See the release notes:

https://www.samba.org/samba/history/samba-3.6.0.html

and the smb.conf and idmap manpages.

Example:
        workgroup = LEVEL1
        realm = LEVEL1.DISCWORLD.SITE
        security = ads

        # v3.6 common id range
        passdb backend = tdbsam
        idmap config * : range = 1000000-1999999

        # Winbind domain idmap
        idmap config LEVEL1 : backend = rid
        idmap config LEVEL1 : range = 100000000-199999999

--- Additional comment from asn@redhat.com on 2012-08-22 15:38:57 CEST ---

The same applies to RHEL 6.4, RHEL 7.0 and Fedora. Should I open a bug for each or will you just clone this bug?

--- Additional comment from tmraz@redhat.com on 2012-08-27 16:55:35 CEST ---

Is the new samba completely backwards incompatible with the old settings?

--- Additional comment from asn@redhat.com on 2012-08-27 17:25:27 CEST ---

No, the old idmap settings will not work anymore. You NEED to change them!
Comment 6 errata-xmlrpc 2013-02-21 06:02:28 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2013-0486.html

Note You need to log in before you can comment on or make changes to this bug.