1 .\" This manpage has been automatically generated by docbook2man
2 .\" from a DocBook document. This tool can be found at:
3 .\" <http://shell.ipoline.com/~elmert/comp/docbook2X/>
4 .\" Please send any bug reports, improvements, comments, patches,
5 .\" etc. to Steve Cheng <steve@ggi-project.org>.
6 .TH "SMBGROUPEDIT" "8" "03 april 2003" "" ""
9 smbgroupedit \- Query/set/change UNIX - Windows NT group mapping
12 \fBsmbroupedit\fR [ \fB-v [l|s]\fR ] [ \fB-a UNIX-groupname [-d NT-groupname|-p privilege|]\fR ]
16 This program is part of the \fBSamba\fR(7) suite.
18 The smbgroupedit command allows for mapping unix groups
19 to NT Builtin, Domain, or Local groups. Also
20 allows setting privileges for that group, such as saAddUser,
25 This option will list all groups available
26 in the Windows NT domain in which samba is operating.
30 give a long listing, of the format:
48 Group type: Local group
50 Privilege : No privilege
54 display a short listing of the format:
58 NTGroupName(SID) -> UnixGroupName
64 Users (S-1-5-32-545) -> -1
71 \fBsmbgroupedit\fR returns a status of 0 if the
72 operation completed successfully, and a value of 1 in the event
76 To make a subset of your samba PDC users members of
77 the 'Domain Admins' Global group:
80 create a unix group (usually in
81 \fI/etc/group\fR), let's call it domadm.
84 add to this group the users that you want to be
85 domain administrators. For example if you want joe, john and mary,
86 your entry in \fI/etc/group\fR will look like:
88 domadm:x:502:joe,john,mary
91 map this domadm group to the 'domain admins' group:
95 Get the SID for the Windows NT "Domain Admins" group:
99 root# \fBsmbgroupedit -vs | grep "Domain Admins"\fR
100 Domain Admins (S-1-5-21-1108995562-3116817432-1375597819-512) -> -1
104 map the unix domadm group to the Windows NT
105 "Domain Admins" group, by running the command:
108 root# \fBsmbgroupedit \\
109 -c S-1-5-21-1108995562-3116817432-1375597819-512 \\
113 \fBwarning:\fR don't copy and paste this sample, the
114 Domain Admins SID (the S-1-5-21-...-512) is different for every PDC.
117 To verify that your mapping has taken effect:
120 root# \fBsmbgroupedit -vs|grep "Domain Admins"\fR
121 Domain Admins (S-1-5-21-1108995562-3116817432-1375597819-512) -> domadm
124 To give access to a certain directory on a domain member machine (an
125 NT/W2K or a samba server running winbind) to some users who are member
126 of a group on your samba PDC, flag that group as a domain group:
129 root# \fBsmbgroupedit -a unixgroup -td\fR
133 This man page is correct for the 3.0alpha releases of
140 The original Samba software and related utilities
141 were created by Andrew Tridgell. Samba is now developed
142 by the Samba Team as an Open Source project similar
143 to the way the Linux kernel is developed.
145 \fBsmbgroupedit\fR was written by Jean Francois Micouleau.
146 The current set of manpages and documentation is maintained
147 by the Samba Team in the same fashion as the Samba source code. The conversion
148 to DocBook XML 4.2 for Samba 3.0 was done by Alexander Bokovoy.