#1588 [RFE] Allow SSSD to be used with smbd shares
Closed: Fixed None Opened 6 years ago by myllynen.

Now that SSSD AD integration (#996) is available it would be desirable to be able to use SSSD instead of Winbind with smbd to allow completely replacing Winbind also on servers providing Samba shares in AD domains. Ideally SSSD could provide the same interfaces Winbind provides today for smbd removing the need for smbd changes/updates thus allowing smooth transition from Winbind to SSSD on Samba servers.

Additionally, this should remove the need for using username map script [1] which is currently required if one wants to mix local/NSS groups and domain groups to restrict access to Samba shares when using security = ads. (This request is forked into a separate ticket #1591)

1) https://lists.samba.org/archive/samba-technical/2012-October/088039.html


Sort of dup of the #1573. I am not sure with one should be closed.

milestone: NEEDS_TRIAGE => SSSD 1.10 beta
priority: major => critical
summary: RFE: Allow SSSD to be used with smbd shares => [RFE] Allow SSSD to be used with smbd shares
type: feature => enhancement

Fields changed

description: Now that SSSD AD integration (#996) is available it would be desirable to be able to use SSSD instead of Winbind with smbd to allow completely replacing Winbind also on servers providing Samba shares in AD domains. Ideally SSSD could provide the same interfaces Winbind provides today for smbd removing the need for smbd changes/updates thus allowing smooth transition from Winbind to SSSD on Samba servers.

Additionally, this should remove the need for using username map script [1] which is currently required if one wants to mix local/NSS groups and domain groups to restrict access to Samba shares when using security = ads.

1) https://lists.samba.org/archive/samba-technical/2012-October/088039.html => Now that SSSD AD integration (#996) is available it would be desirable to be able to use SSSD instead of Winbind with smbd to allow completely replacing Winbind also on servers providing Samba shares in AD domains. Ideally SSSD could provide the same interfaces Winbind provides today for smbd removing the need for smbd changes/updates thus allowing smooth transition from Winbind to SSSD on Samba servers.

Additionally, this should remove the need for using username map script [1] which is currently required if one wants to mix local/NSS groups and domain groups to restrict access to Samba shares when using security = ads. (This request is forked into a separate ticket #1591)

1) https://lists.samba.org/archive/samba-technical/2012-October/088039.html

Fields changed

rhbz: => todo

Might be a dup of #1573.

design: =>
design_review: => 0
fedora_test_page: =>
selected: => May

Fields changed

priority: critical => major

Fields changed

milestone: SSSD 1.10 beta => SSSD 1.11 beta
review: => 0

Fields changed

changelog: =>
milestone: SSSD 1.12 beta => Interim Bucket

Fields changed

priority: major => critical

Fields changed

milestone: Interim Bucket => SSSD 1.12 beta

Fields changed

owner: somebody => sbose
status: new => assigned

Please rescope if something is missing or close if everything will be done in Samba. Thanks!

milestone: SSSD 1.12 beta => NEEDS_TRIAGE

I'm working to get the support into samba upstream but it would be nice to keep this ticket as a tracker. I've changed the type to task to indicate that no coding is needed here.

type: enhancement => task

Fields changed

milestone: NEEDS_TRIAGE => SSSD 1.13 beta

Fields changed

milestone: SSSD 1.13 beta => NEEDS_TRIAGE

Fields changed

milestone: NEEDS_TRIAGE => SSSD 1.12.1

Fields changed

patch: 0 => 1

resolution: => fixed
status: assigned => closed

Metadata Update from @myllynen:
- Issue assigned to sbose
- Issue set to the milestone: SSSD 1.12.1

2 years ago

Login to comment on this ticket.

Metadata