Automatically mapping UNIX users from LDAP to Windows users
To automatically map UNIX users from LDAP to Windows users
- Ensure that Access Appliance joins the LDAP domain using network ldap.
From the LDAP server, users and groups should be visible by using the getent passwd or getent group commands .
- Ensure that Access Appliance joins the Windows AD domain using cifs.
- Use the wildcard mapping rule CIFS> mapuser add * AD Domain Name *.
The effect is whenever a Windows domain user, say
DOM\foobar, wants to access CIFS shares, the CIFS server determines if there is a local (a non-Windows) user also namedfoobar, and establishes the mapping between the Windows user and the non-Windows user.The user name must match between the LDAP and AD domains.