NAME
idmapnss - Samba's idmapnss Backend for Winbind
DESCRIPTION
The idmapnss plugin provides a means to map Unix users and groups to Windows accounts and obseletes the "winbind trusted domains only" smb.conf option. This provides a simple means of ensuring that the SIDfor a Unix user named jsmith is reported as the one assigned to DOMAIN-
jsmith which is necessary for reporting ACLs on files and printers stored on a Samba member server. EEXXAAMMPPLLEESS This example shows how to use idmapnss to check the local accounts for its own domain while using allocation to create new mappings for trusted domains [global] idmap domains = SAMBA TRUSTEDDOMAINS idmap config SAMBA:backend = nss idmap config SAMBA:readonly = yes idmap config TRUSTEDDOMAINS:default = yes idmap config TRUSTEDDOMAINS:backend = tdbidmap config TRUSTEDDOMAINS:range = 10000 - 50000
idmap alloc backend = tdbidmap alloc config:range = 10000 - 50000
AUTHOR The original Samba software and related utilities were created by Andrew Tridgell. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed. IDMAPNSS(8)