Не менять, а добавлять…
https://wiki.samba.org/index.php/Setup_Samba_as_an_AD_Domain_Member#libnss_winbind
где-то какой-то закорючки не хватает, не работает (как по ссылке getent не отдает списки домена), вот какие конфиги на данный момент:
smb.conf
# Global parameters
[global]
workgroup = SET
realm = SET.DOMAIN.COM
security = ADS
map to guest = Bad User
obey pam restrictions = Yes
pam password change = Yes
passwd program = /usr/bin/passwd %u
passwd chat = *Enter\snew\s*\spassword:* %n\n *Retype\snew\s*\spassword:* %n\n *password\supdated\ssuccessfully* .
unix password sync = Yes
syslog = 0
log file = /var/log/samba/log.%m
max log size = 1000
os level = 0
preferred master = No
local master = No
domain master = No
dns proxy = No
usershare allow guests = Yes
panic action = /usr/share/samba/panic-action %d
winbind enum users = Yes
winbind enum groups = Yes
winbind use default domain = Yes
winbind nss info = rfc2307
winbind refresh tickets = Yes
winbind offline logon = Yes
idmap config set : backend = ad
idmap config set : schema_mode = rfc2307
idmap config set : range = 10000-99999
idmap config * : range = 2000-9999
idmap config * : backend = tdb
[printers]
comment = All Printers
path = /var/spool/samba
create mask = 0700
printable = Yes
browseable = No
[print$]
comment = Printer Drivers
path = /var/lib/samba/printers
nsswitch.conf
passwd: compat winbind
group: compat winbind
shadow: compat
gshadow: files
hosts: files mdns4_minimal [NOTFOUND=return] dns
#hosts: dns mdns4_minimal [NOTFOUND=return] mdns4 files
networks: files
protocols: db files
services: db files
ethers: db files
rpc: db files
netgroup: nis
Пользователь добавил сообщение 02 Августа 2016, 07:03:24:
еще почему-то testparm видит строки
idmap config SET : backend = ad
idmap config SET : schema_mode = rfc2307
idmap config SET : range = 10000-99999
как
idmap config set : backend = ad
idmap config set : schema_mode = rfc2307
idmap config set : range = 10000-99999
хотя здесь
workgroup = SET
realm = SET.DOMAIN.COM
security = ADS
регистр не изменен.