Hottest Free Downloads - DownloadPipe.com Over 197,000 downloads! Bookmark Now!
DownloadPipe.com - New Downloads Every Minute
 SEARCH:
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

[Samba] Winbind lookup performance

 
   Linux (Home) -> Samba RSS
Next:  Accepted libclass-method-modifiers-perl 1.05-1 (s..  
Author Message
Matthew J. Salerno

External


Since: Oct 09, 2009
Posts: 6



(Msg. 1) Posted: Thu Oct 22, 2009 2:25 pm
Post subject: [Samba] Winbind lookup performance
Archived from groups: linux>samba (more info?)

Redhat 5.2 x86_64
samba-3.0.28-0.el5.8

My system is fully AD integrated, the only issue I have is that when I look up a users group (id, groups, etc.) it takes forever.  This is causing issues due to the fact that I have pam policies in place to allow only users from a specific groups to log in, sudo and/or su.  When the cache expires, it can take over 2 minutes to perform the lookup.  I'm sure it doesn't help that my AD user account is a member of 120 different groups.  I would imagine that if I could use a custom, more exclusive LDAP filter for the winbind module I could improve performance, but I don't believe that option is available.

Is there a way for speeding up the lookup process?

Thanks

[global]
        workgroup = DOMAIN
        realm = DOMAIN.NET
        server string = Samba file and print server
        security = ADS
        log level = 3
        max log size = 4192
        large readwrite = No
        max xmit = 65535
        client signing = Yes
        server signing = Yes
        deadtime = 15
        socket options = TCP_NODELAY IPTOS_LOWDELAY TCP_NODELAY
        printcap name = cups
        preferred master = No
        idmap domains = DOMAIN
        idmap backend = tdb
        idmap alloc backend = tdb
        idmap cache time = 302400
        idmap negative cache time = 600
        template shell = /bin/bash
        winbind separator = +
        winbind cache time = 1800
        winbind enum users = Yes
        winbind enum groups = Yes
        winbind nested groups = No
        winbind refresh tickets = Yes
        winbind offline logon = Yes
        winbind normalize names = Yes
        idmap config DOMAIN:default = yes
        idmap config DOMAIN:backend = rid
        idmap config DOMAIN:range = 5000-9999999
        idmap config DOMAINN:cache time = 1800
        idmap alloc config:range = 4000 - 4999




--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
Back to top
Login to vote
Matthew J. Salerno

External


Since: Oct 09, 2009
Posts: 6



(Msg. 2) Posted: Thu Oct 22, 2009 3:25 pm
Post subject: Re: [Samba] Winbind lookup performance [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

----- Original Message ----
From: Matthew J. Salerno <vagabond_king.RemoveThis@yahoo.com>
To: samba.RemoveThis@lists.samba.org
Sent: Thu, October 22, 2009 1:19:59 PM
Subject: [Samba] Winbind lookup performance

Redhat 5.2 x86_64
samba-3.0.28-0.el5.8

My system is fully AD integrated, the only issue I have is that when I look up a users group (id, groups, etc.) it takes forever.  This is causing issues due to the fact that I have pam policies in place to allow only users from a specific groups to log in, sudo and/or su.  When the cache expires, it can take over 2 minutes to perform the lookup.  I'm sure it doesn't help that my AD user account is a member of 120 different groups.  I would imagine that if I could use a custom, more exclusive LDAP filter for the winbind module I could improve performance, but I don't believe that option is available.

Is there a way for speeding up the lookup process?

Thanks

[global]
        workgroup = DOMAIN
        realm = DOMAIN.NET
        server string = Samba file and print server
        security = ADS
        log level = 3
        max log size = 4192
        large readwrite = No
        max xmit = 65535
        client signing = Yes
        server signing = Yes
        deadtime = 15
        socket options = TCP_NODELAY IPTOS_LOWDELAY TCP_NODELAY
        printcap name = cups
        preferred master = No
        idmap domains = DOMAIN
        idmap backend = tdb
        idmap alloc backend = tdb
        idmap cache time = 302400
        idmap negative cache time = 600
        template shell = /bin/bash
        winbind separator = +
        winbind cache time = 1800
        winbind enum users = Yes
        winbind enum groups = Yes
        winbind nested groups = No
        winbind refresh tickets = Yes
        winbind offline logon = Yes
        winbind normalize names = Yes
        idmap config DOMAIN:default = yes
        idmap config DOMAIN:backend = rid
        idmap config DOMAIN:range = 5000-9999999
        idmap config DOMAINN:cache time = 1800
        idmap alloc config:range = 4000 - 4999



     
--
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba



I removed winbind enum users = Yes and winbind enum groups = Yes and it seems to be much faster.  Now I just need ot make sure everything else is still working as expected.



--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
Back to top
Login to vote
Robert LeBlanc

External


Since: Oct 17, 2009
Posts: 4



(Msg. 3) Posted: Thu Oct 22, 2009 8:25 pm
Post subject: Re: [Samba] Winbind lookup performance [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On Thu, Oct 22, 2009 at 12:29 PM, Matthew J. Salerno <
vagabond_king.TakeThisOut@yahoo.com> wrote:

>
> I removed winbind enum users = Yes and winbind enum groups = Yes and it
> seems to be much faster. Now I just need ot make sure everything else is
> still working as expected.
>
> When dealing with a large amount of objects, you will want enum users and
groups off. We don't use it here and everything works fine.

Robert LeBlanc
Life Sciences & Undergraduate Education Computer Support
Brigham Young University
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba
Back to top
Login to vote
Display posts from previous:   
Related Topics:
[Samba] xp lookup - Hi all, I am using samba, and I'd tried it with Windows versions: 98 and XP, in that order. Everthing works fine, excepting that when I am using the samba shares (browsing, opening files, etc...) from time to time I get a temp lockup. During that time...

[Samba] repeating 'lp' group lookup. - hello. i have configured samba 3.0.14a for sharing users homes with winbind authenticate. winbind works fine, but i cannot start smbd. it just hatled on startup with following messages: -------- [2005/06/16 12:04:10, 4] param/loadparm.c:lp_load(3938) ...

[Samba] nsswitch wins reverse lookup - I don't get reverse lookups (gethostbyaddr) over winbind wins to work. Normal lookups work and also wbinfo -I gives back a netbios name for an IP. my entry in nsswitch.conf is hosts: files dns wins (dns reverse lookups ar ok) The wins server....

[Samba] poor performance with bonding in round-robin mode .. - Hi, samba 3.0.24, debian etch I'm seeing a strange effect with samba and traffic over a bond0 interface in round robin mode. 2 server each with 2 GbE interfaces as bond0 device ind rr mode. netio benchmark: NETIO - Network Throughput Benchmark,..

[Samba] Horrible write performance from XP to Samba - I noted an extremely poor performance when copying big files from a windows xp client to a samba share. The exact version of samba does not seem to matter: I tried several different samba servers with versions between 3.014 and 3.0.23b running on Linux..
       Linux (Home) -> Samba All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Categories:
 Windows Forums
 Game Forums
  Linux Forums
 Mac Forums
 PDA Forums
 Mobile Forums
  Top  |  Store  |  RSS Feeds RSS  |  Data Feeds  |  Advertise  |  Submit  |  Bookmark  |  Newsletter  |  Contact