2012-07-26 02:27 PM
I try to map Unix useraccounts to Windows useraccounts, both in the same Active Directory.
Filer: Ontap 8.1P2
Active Directory: Windows 2008 R2
MY-DOMAIN\testuser == testuser
MY-DOMAIN\* == *
hosts: files dns nis
passwd: files ldap nis
netgroup: files ldap nis
group: files ldap nis
shadow: files nis
wcc -s testuser
(NT - UNIX) account name(s): (MY-DOMAIN\testuser - pcuser)
UNIX uid = 65534
User is also a member of Everyone, Network Users,
wcc -u testuser
no passwd entry for testuser
getXXbyYY getpwbyname_r testuser
Could not get passwd entry for name = testuser
Has anyone an idea what could be wrong?
2012-07-31 01:19 AM
I could solve the problem.
After installing the Unix Services role on one of the domain controllers, there is a new tab "UNIX Attributes" in the "Active Directory Users and Computers" tool. There I had to fill out all fields like NIS Domain, UID, Login Shell, Home Directory and GID. It's not enough to set the corresponding fields in the "Attribute Editor".
2012-08-02 08:08 AM
Be aware that installing SFU also extends your schema. The RFC2307 objects and attributes are already in Windows 2003R2 or later, the only thing SFU gives you is an easy way to edit those attributes.
In addition you probably want to change the following
Finally if you have multiple domains you want to connect on the Global Catalog port (3268 or 3269 with SSL) and to make sure the attributes in your NSS maps are replicated to GCs.