Univention Bugzilla – Bug 33345
In place upgrade of the Samba 3/NT4 to a Samba 4/AD domain - user sid's were changed during migration
Last modified: 2013-11-13 12:01:39 CET
-> univention-ldapsearch uid=testxp sambaSid dn: uid=testxp,cn=users,dc=perf,dc=test sambaSID: S-1-5-21-2258647891-1754753931-3671923481-11127 uidNumber: 2007 -> univention-s4search cn=testxp objectSid dn: CN=testxp,CN=Users,DC=perf,DC=test objectSid: S-1-5-21-2258647891-1754753931-3671923481-11127 -> ldbsearch -H /var/lib/samba/private/idmap.ldb \ objectSid=S-1-5-21-2258647891-1754753931-3671923481-11127 # record 1 dn: CN=S-1-5-21-2258647891-1754753931-3671923481-11127 cn: S-1-5-21-2258647891-1754753931-3671923481-11127 objectClass: sidMap objectSid: S-1-5-21-2258647891-1754753931-3671923481-11127 type: ID_TYPE_UID xidNumber: 2007 distinguishedName: CN=S-1-5-21-2258647891-1754753931-3671923481-11127 -> samba-tool ntacl get /home/testxp| grep sid WARNING: No path in service IPC$ - making it unavailable! NOTE: Service IPC$ is flagged unavailable. owner_sid : * owner_sid : S-1-5-21-2258647891-1754753931-3671923481-5014 group_sid : * group_sid : S-1-5-21-2258647891-1754753931-3671923481-513 -> more /var/log/univention/listener.log | grep 5014 13.11.13 09:30:56.029 LISTENER ( PROCESS ) : samba4-idmap: added entry for S-1-5-21-2258647891-1754753931-3671923481-5014 13.11.13 09:33:03.883 LISTENER ( PROCESS ) : samba4-idmap: renaming entry for S-1-5-21-2258647891-1754753931-3671923481-5014 to S-1-5-21-2258647891-1754753931-3671923481-11127
connector-s4.log shows thath the user was not exported to samba during the classicupgrade: =============================================================================== 13.11.2013 09:32:36,715 LDAP (PROCESS): sync from ucs: [ user] [ add] cn=testxp,cn=users,dc=perf,dc=test =============================================================================== And a bit later, shortly before the listener detects the sambaSID change: =============================================================================== 13.11.2013 09:33:03,547 LDAP (PROCESS): sync to ucs: [ user] [ modify] uid=testxp,cn=users,dc=perf,dc=test ===============================================================================
Part of Bug #33338 *** This bug has been marked as a duplicate of bug 33338 ***