I am using 9.2.1.5. I have LDAP set up and things like SSH are working fine. getent passwd/group shows me all my ldap users and groups. However, CIFS isn't working right. It does appear to grab the ldap user and primary group. However, it won't read any other groups. So if I have a folder/file that has permissions for, say, group1, if a user does not have group1 as their primary group, even if they are a part of that group otherwise, they cannot access that folder/file.
Has anyone run into this yet? I'm not sure what info I can give you. Here is what smb.conf looks like:
[global]
server max protocol = SMB3
encrypt passwords = yes
dns proxy = no
strict locking = no
oplocks = yes
deadtime = 15
max log size = 51200
max open files = 11070
load printers = no
printing = bsd
printcap name = /dev/null
disable spoolss = yes
getwd cache = yes
guest account = www
map to guest = Bad User
obey pam restrictions = Yes
directory name cache size = 0
kernel change notify = no
panic action = /usr/local/libexec/samba/samba-backtrace
server string = FreeNAS Server
ea support = yes
store dos attributes = yes
map archive = no
map readonly = no
map hidden = no
map system = no
unix extensions = no
acl allow execute always = true
server role = member server
security = user
passdb backend = ldapsam:ldap://172.16.10.11
ldap admin dn = uid=auth,ou=System,dc=boxcarpress,dc=com
ldap suffix = dc=boxcarpress,dc=com
ldap user suffix = ou=people
ldap group suffix = ou=groups
ldap machine suffix = ou=computers
ldap ssl = off
ldap replication sleep = 1000
ldap passwd sync = yes
ldapsam:trusted = yes
idmap uid = 10000-39999
idmap gid = 10000-39999
netbios name = OFFICE1
workgroup = WORKGROUP
pid directory = /var/run/samba
smb passwd file = /var/etc/private/smbpasswd
private dir = /var/etc/private
create mask = 0666
directory mask = 0777
client ntlmv2 auth = yes
dos charset = CP437
unix charset = iso-8859-1
log level = 3
[office]
path = /mnt/boxraid/office
printable = no
veto files = /.snap/.windows/.zfs/
writeable = yes
browseable = yes
inherit owner = no
inherit permissions = no
recycle:repository = .recycle/%U
recycle:keeptree = yes
recycle:versions = yes
recycle:touch = yes
recycle:directory_mode = 0777
recycle:subdir_mode = 0700
vfs objects = zfsacl streams_xattr aio_pthread
hide dot files = yes
guest ok = no
inherit acls = yes
nfs4:mode = special
nfs4:acedup = merge
nfs4:chown = yes
zfsacl:acesort = dontcare
Has anyone run into this yet? I'm not sure what info I can give you. Here is what smb.conf looks like:
[global]
server max protocol = SMB3
encrypt passwords = yes
dns proxy = no
strict locking = no
oplocks = yes
deadtime = 15
max log size = 51200
max open files = 11070
load printers = no
printing = bsd
printcap name = /dev/null
disable spoolss = yes
getwd cache = yes
guest account = www
map to guest = Bad User
obey pam restrictions = Yes
directory name cache size = 0
kernel change notify = no
panic action = /usr/local/libexec/samba/samba-backtrace
server string = FreeNAS Server
ea support = yes
store dos attributes = yes
map archive = no
map readonly = no
map hidden = no
map system = no
unix extensions = no
acl allow execute always = true
server role = member server
security = user
passdb backend = ldapsam:ldap://172.16.10.11
ldap admin dn = uid=auth,ou=System,dc=boxcarpress,dc=com
ldap suffix = dc=boxcarpress,dc=com
ldap user suffix = ou=people
ldap group suffix = ou=groups
ldap machine suffix = ou=computers
ldap ssl = off
ldap replication sleep = 1000
ldap passwd sync = yes
ldapsam:trusted = yes
idmap uid = 10000-39999
idmap gid = 10000-39999
netbios name = OFFICE1
workgroup = WORKGROUP
pid directory = /var/run/samba
smb passwd file = /var/etc/private/smbpasswd
private dir = /var/etc/private
create mask = 0666
directory mask = 0777
client ntlmv2 auth = yes
dos charset = CP437
unix charset = iso-8859-1
log level = 3
[office]
path = /mnt/boxraid/office
printable = no
veto files = /.snap/.windows/.zfs/
writeable = yes
browseable = yes
inherit owner = no
inherit permissions = no
recycle:repository = .recycle/%U
recycle:keeptree = yes
recycle:versions = yes
recycle:touch = yes
recycle:directory_mode = 0777
recycle:subdir_mode = 0700
vfs objects = zfsacl streams_xattr aio_pthread
hide dot files = yes
guest ok = no
inherit acls = yes
nfs4:mode = special
nfs4:acedup = merge
nfs4:chown = yes
zfsacl:acesort = dontcare