AD integration - No domain users or groups in the GUI

Status
Not open for further replies.

jabbs

Cadet
Joined
Dec 7, 2015
Messages
6
Hi,

I am having trouble with my latest FreeNAS build. I am using build 9.10-STABLE-201606072003. The build was smooth, I have successfully joined my FreeNAS box to my Windows 2008 R2 domain. My problem is that some AD users are not visible when changing permissions in the GUI.

I appreciate there are other post covering very similar topics, however in the vast majority people experience issues retrieving AD information using wbinfo and getent. I see domain users just fine when running wbinfo -u, I see domain groups when executing wbinfo -g. Getent displays AD information as expected.

I have compared one of the AD accounts which I can see with one I cannot, specifically looking at security settings - there's nothing I can see which should affect this. Unless I have missed something I couldn't see anything in any documentation about having to do anything specific before AD user objects will appear.

I'm obviously far from a FreeNAS expert, but short of some fairly fundamental issues I had with the first FreeNAS box I have built, the others have all gone smoothly.

Couple of further points worth mentioning:

  • New AD user accounts I create ARE visible.
  • Rebuilding the cache hasn't made any difference, sadly.
  • I have monitored /var/log/messages for errors during the domain join but there are none at all.
  • I have compared smb4.conf with one from another working FreeNAS server (same build), no issues there.
  • Compared all networking, storage, services and share information with a working FreeNAS server, no differences I can see.
  • I reinstalled FreeNAS, although admittedly I did restore my config as opposed to starting from scratch.

Does anyone please have any suggestions as to why I see some AD users/groups and not others? I'm a bit desperate at this point. Having some AD authentication is better than none, but as this is (or will be) a mirrored copy of another FreeNAS server, I want to make sure all permissions are identical so as to allow easy failover when needed.

Many thanks,
Jason
 

jabbs

Cadet
Joined
Dec 7, 2015
Messages
6
In 9.3, a full list of all local and AD users/groups were populated in the drop-down list when changing permissions on a dataset (assuming AD integration is working). All local users/groups listed first, then all domain users/groups, each listed alphabetically.

In 9.10 (or at least on my 9.10 box) it is a little different. Local users/groups are listed first and AD users/groups aftewards, but only *some* AD users/groups are listed. Both the users and group drop-down lists seem limited at 50 entries. In previous versions this wasn't the case, at least in my experience.

It seems like just a bug(?) in the GUI, as typing in the domain account works fine even if it isn't listed. I should obviously have tried this earlier, but I was used to selecting users from the list given that all imported users should be visible.

Obviously not a major issue but worth mentioning in case anyone is as dim as me and runs into the same :)
 

Mirfster

Doesn't know what he's talking about
Joined
Oct 2, 2015
Messages
3,215
Give this a whirl:

Per the 9.10 Manual:
If the wbinfo commands display the network’s users, but they do not show up in the drop-down menu of a Permissions
screen, it may be because it is taking longer then the default 10 seconds for the FreeNAS® system to join Active
Directory. Try bumping up the value of “AD timeout” to 60 seconds.
 

jabbs

Cadet
Joined
Dec 7, 2015
Messages
6
Thanks for the reply Mirfster, good suggestion. I should have mentioned earlier that I did try changing that value and unfortunately it made no difference.

I suspect a bug in the GUI, those user/group drop-down list just seem limited to 50 entries. Probably no biggie for most unless integrating with AD. I'm about to build another 9.10 box, I'll see if the same happens there too
 

anodos

Sambassador
iXsystems
Joined
Mar 6, 2014
Messages
9,554
Thanks for the reply Mirfster, good suggestion. I should have mentioned earlier that I did try changing that value and unfortunately it made no difference.

I suspect a bug in the GUI, those user/group drop-down list just seem limited to 50 entries. Probably no biggie for most unless integrating with AD. I'm about to build another 9.10 box, I'll see if the same happens there too

You can actually click in those fields and type usernames and groups. It will even auto-complete. I reported this as a bug and was told that it was designed this way. IMHO, this is handled much better in freenas 10.
 

Mirfster

Doesn't know what he's talking about
Joined
Oct 2, 2015
Messages
3,215

jabbs

Cadet
Joined
Dec 7, 2015
Messages
6
Yes I did notice, albeit a day later than I should :)

The scroll bar within the drop-down easily handled 100's of accounts in previous versions, but its a minor thing. If I hadn't been used to selecting the account from the drop-down I would have typed the account in straightaway. I doubt many/any will run into the same issue.

Thanks for the comments, appreciate the time
 
Status
Not open for further replies.
Top