--dFWYt1i2NyOo1oI9
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Thu, Sep 16, 2004 at 11:56:34AM +1000, Andrew Bartlett wrote:

> > So if the ntlm_auth tool is enhanced to return the group information, w=

ould=20
> > it be just a list of SIDs or it could be the actual group names? If it =

will=20
> > be SIDs, do we need to query the domain controllers for the groupnames,=

or=20
> > Samba has other API we can use to do the conversion?

>=20
> My suggestion is that we would return SIDs only, and that you would
> convert the names that you store for ACLs into SIDs, for comparison. =20
> (The reason we would only return the SIDs is to avoid the extra network
> cost.)


Maybe add a -n option to the ntlm_auth program?


Tim.

--dFWYt1i2NyOo1oI9
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFBSPbPLjpWbwciAh4RAtiLAKCtI5Aqb/EBsdveuNblTPOKJa3kCgCfQKgv
t8eXVpfXQChJRQLDGiDBVzQ=
=NjZV
-----END PGP SIGNATURE-----

--dFWYt1i2NyOo1oI9--