[Pkg-samba-maint] Bug#491686: closed by Steve Langasek <vorlon at debian.org> (Re: base: the command "groups" doesn't shows local groups using pam_winbind.so authentication module)

Steve Langasek vorlon at debian.org
Wed Jul 23 18:08:59 UTC 2008

On Tue, Jul 22, 2008 at 08:53:05AM +0200, Paolo Sala wrote:
> Debian Bug Tracking System scrisse in data 21/07/2008 20:27:
>> pam_winbind has nothing to do with group membership.  You also need to
>> enable nss_winbind in /etc/nsswitch.conf to resolve domain groups.

> I have already done it. In my nsswitch.conf I have "group: files  
> winbind". I have opened a bug report because the problem has come up  
> when I have upgraded my etch to lenny. Before the upgrade the group  
> authentication was working without problem.

> I don't know where the problem is but I'm pretty sure is not in samba:  
> winbind resolve users and remote group membership, but doesn't work the  
> membership of a remote user in a local group. So all software that need  
> group authentication doesn't work: I think is a important bug.  
> Furthermore if I log in as a local user the group authentication works  
> without problem.

You mention a remote user in a local group; so this means you have the user
listed in /etc/groups?  And the command 'groups $remoteuser' shows only the
remote group memberships, not the local ones?

Can you send the contents of your /etc/nsswitch.conf file?

Steve Langasek                   Give me a lever long enough and a Free OS
Debian Developer                   to set it on, and I can move the world.
Ubuntu Developer                                    http://www.debian.org/
slangasek at ubuntu.com                                     vorlon at debian.org

More information about the Pkg-samba-maint mailing list