First page Back Continue Last page Overview Graphics
Why must we map principals ?
In order to do any access control, principals in the Windows clients must be mapped to POSIX principals.
- This mapping is done within Samba by principal name lookups.
- Windows internal principal format <-----> Windows principal name <-----> POSIX principal name <-----> POSIX internal principal format.
- Sometimes the Windows internal principal format (SID) is passed directly to Samba.
- Lookups must then be done to an identifying authority (a “Domain Controller' in Windows terms.
- But what do we do if the Domain Controller is not contactable... ?