NFS on 11.2-RELEASE can't add Active Directory Groups

rumbeard

Dabbler
Joined
Sep 10, 2018
Messages
17
So I've had AD groups in the drop-down and have been able to add them as a mapall group for many releases up to 11.1 U6. Upgraded and now it says the groups don't exist. First clue was the dreaded DOMAIN<Group> without the backslash showing up in a mountd error on the console. If I try to add them in the new GUI I see no AD groups. If I use the legacy GUI I see all the AD groups, but they say group does not exist upon save. I also came up with a blank /etc/exports upon upgrade. Changing one share re-populated everything, but again I get five group does not exist messages. Kind of lost on this one.
 
Last edited:

anodos

Sambassador
iXsystems
Joined
Mar 6, 2014
Messages
9,554
So I've had AD groups in the drop-down and have been able to add them as a mapall group for many releases up to 11.1 U6. Upgraded and now it says the groups don't exist. First clue was the dreaded DOMAIN<Group> without the backslash. If I try to add them in the new GUI I see no AD groups. If I use the legacy GUI I see all the AD groups, but they say group does not exist upon save. I also came up with a blank /etc/exports upon upgrade. Changing one share re-populated everything, but again I get five group does not exist messages. Kind of lost on this one.
Can you PM me a debug file?
 

rumbeard

Dabbler
Joined
Sep 10, 2018
Messages
17
Sure, how should I generate that?

Some extra info:

wbinfo -u and wbinfo -g work, and ls -l shows AD users and groups resolving. All SMB shares function correctly with Windows permissions/ACL.
 

anodos

Sambassador
iXsystems
Joined
Mar 6, 2014
Messages
9,554
Sure, how should I generate that?

Some extra info:

wbinfo -u and wbinfo -g work, and ls -l shows AD users and groups resolving. All SMB shares function correctly with Windows permissions/ACL.
It sounds like an issue with the freenas-cache. You can try regenerating it under Directory Service -> Active Directory to see if it resolves your issue.
 

rumbeard

Dabbler
Joined
Sep 10, 2018
Messages
17
I tried this. Still no AD groups in new interface and present in old interface. Click save. Unknown group.
Message on console looks like this:

Domain is VALHALLA, dadm is group. Created nested due to spaces issue for Domain Admins
 

Attachments

  • Screen Shot 2018-12-17 at 21.34.35.png
    Screen Shot 2018-12-17 at 21.34.35.png
    927.2 KB · Views: 511

rumbeard

Dabbler
Joined
Sep 10, 2018
Messages
17
AD config
 

Attachments

  • Screen Shot 2018-12-17 at 21.40.19.png
    Screen Shot 2018-12-17 at 21.40.19.png
    706.5 KB · Views: 461
  • Screen Shot 2018-12-17 at 21.41.13.png
    Screen Shot 2018-12-17 at 21.41.13.png
    706.4 KB · Views: 489

mikesm

Dabbler
Joined
Mar 20, 2013
Messages
36
I have a similar problem with 11.2. In the NFS sharing config, I can't set the mapall user to a windows domain user, and they don't show up in users or groups in accounts.
 

rumbeard

Dabbler
Joined
Sep 10, 2018
Messages
17
Rejoining the domain fixed this only for volume/dataset permissions, but still the same issue.
 
Top