Announcement Banner
UNSOLVED

havechuco

updated

8 years ago

H

havechuco

1 Message

0

619

July 2nd, 2018 12:00

Authentication providers - SMB

Hello all,

We just migrated our data to a new gen6 cluster running 8.1.0.3. I set up one domain as AD auth provider for the zone containing the data.

The added domain has a forest wide 2-way trust with several other domains containing users and groups that need access to the files as well. When testing permissions for users, only users and groups belonging to the AD auth provider can modify files. Onefs will not authenticate users and groups from other domains.

Has anyone done anything similar to this with success? I would like to figure out a way to do it without changing permissions on all of the files to match only the primary domain.

Thanks

  • crklosterman

    450 Posts

    399

    0

    Posted July 3rd, 2018 06:00

    Does the domain that it's joined to have RFC2307 enabled (aka SFU [Services for Unix]), and the other domains in the trust do not?   I've seen this kind of behavior before in such a situation.  The cluster needs a valid (or made up) UID, GID and SID for every user that connects.  A good way to test is to use the 'isi auth mapping token domain\\username' command.  It's a great troubleshooting tool.  Also, FWIW you might want to take a look at 8.1.0.4, I think that it was just released with some important fixes.

    ~Chris Klosterman

    Principal SE, Datadobi

    chris.klosterman@datadobi.com