samba-users August 2010 archive
Main Archive Page > Month Archives  > samba-users archives
samba-users: [Samba] UID syncing issues with CTDB

[Samba] UID syncing issues with CTDB

From: Jeremy Farrar <jeremy.farrar_at_nospam>
Date: Tue Aug 17 2010 - 15:26:05 GMT

I have been working on a CTDB cluster on and off for a while now. I had it
working great for a while. THen I decide dthat I wanted to change the
configuration of my replicated volumes. I changed my DRBD configuration to
match my desired configuration. Now I can get the CTDB to work quite right.
I am able to join the cluster to the domain without issues. I can also list
my ad users and groups using wbinfo so I believe that my nsswitch.conf is
set up properly. I am having problems with the UIDs and GIDs not matching
between the two servers. For instance here is the output for getent on each

Server A:
jfarrar:*:20066:20001:Jeremy Farrar:/home/DOMAIN/jfarrar:/bin/bash

Server B:
jfarrar:*:20002:20001:Jeremy Farrar:/home/DOMAIN/jfarrar:/bin/bash

The output looks good but the UID doesn't match. This will lead to some
weird permissions issues in the future. THe strange thing is that it worked
before. What did I mess up when I reconfigured my volume? Thanks for your


   server string = %h
   workgroup = DOMAIN
   netbios name = server
   password server = dc1.domain.local
   realm = DOMAIN.LOCAL
   security = ads
   idmap backend = tdb2
   idmap uid = 10000-20000
   idmap gid = 10000-20000
   template shell = /bin/bash
    template homedir = /home/DOMAIN/%U
   winbind uid = 20001-200000
   winbind gid = 20001-200000
   winbind trusted domains only = no
   winbind use default domain = true
   winbind offline logon = false
   winbind enum users = yes
   winbind enum groups = yes
   obey pam restrictions = yes
   printcap name = /etc/printcap
   clustering = yes
   # logs split per machine
   log file = %S.log
   log level = 2
   # max 50KB per log file, then rotate
   max log size = 50

    passdb backend = tdbsam

#============================ Share Definitions

    comment = Home Directories
    path = /DOMAIN
    browseable = no
    writable = yes
# acl compatibility = auto
    acl check permissions = True
    nt acl support = yes
    ea support = yes
    acl map full control = True
    map acl inherit = yes
    inherit acls = yes


passwd: files winbind
shadow: files winbind
group: files winbind

hosts: files dns

bootparams: nisplus [NOTFOUND=return] files

ethers: files
netmasks: files
networks: files
protocols: files
rpc: files
services: files

netgroup: files

publickey: nisplus

automount: files
aliases: files nisplus


  ulimit -n 10000
-- To unsubscribe from this list go to the following URL and read the instructions: