AnrDaemon / samba4-ads

1 stars 1 forks source link

Needs script to synchronize sam and idmap databases #11

Open AnrDaemon opened 9 years ago

AnrDaemon commented 9 years ago

Need to write automatic script to fix idmap/sam #7 discrepacy. Fixing that shit by hands is error-prone and not really lead to anything good.

AnrDaemon commented 9 years ago

Ref: https://support.microsoft.com/en-us/kb/243330 There looks to be 3 major idmap blocks.

Assuming custom SID's in range 30000+ (any sufficiently high range, in fact), the plan is to use 5xx range for 5xx SID's and let user choose range for global SID's. 1xxxx would probably work well.

AnrDaemon commented 9 years ago

The only default SID I know that doesn't fit the 5xx scheme is Enterprise Read-only Domain Controllers (S-1-5- 21-…-498). Given it is a Windows 2008 group and RODC's are not currently supported, it falls within the first category.

AnrDaemon commented 9 years ago

SAM is authoritative for remapping!