
Attachment uploads are currently disabled. This is a temporary situation and will resume as normal in the coming days.
UNSOLVED
Authentication providers - SMB
Hello all,
We just migrated our data to a new gen6 cluster running 8.1.0.3. I set up one domain as AD auth provider for the zone containing the data.
The added domain has a forest wide 2-way trust with several other domains containing users and groups that need access to the files as well. When testing permissions for users, only users and groups belonging to the AD auth provider can modify files. Onefs will not authenticate users and groups from other domains.
Has anyone done anything similar to this with success? I would like to figure out a way to do it without changing permissions on all of the files to match only the primary domain.
Thanks
Responses (1)
Solutions (0)

crklosterman
450 Posts
399
0
Posted July 3rd, 2018 06:00
Does the domain that it's joined to have RFC2307 enabled (aka SFU [Services for Unix]), and the other domains in the trust do not? I've seen this kind of behavior before in such a situation. The cluster needs a valid (or made up) UID, GID and SID for every user that connects. A good way to test is to use the 'isi auth mapping token domain\\username' command. It's a great troubleshooting tool. Also, FWIW you might want to take a look at 8.1.0.4, I think that it was just released with some important fixes.
~Chris Klosterman
Principal SE, Datadobi
chris.klosterman@datadobi.com