Por que existem tantas coisas não descobertas? e por que dis seu ligante mínimo levon anonymus?
Deixe um usuário dedicatet fazer tudo isso.
Aqui está minha configuração:
filer1> options ldap
ldap.ADdomain foo.com
ldap.base dc=foo,dc=com
ldap.base.group dc=foo,dc=com
ldap.base.netgroup dc=foo,dc=com
ldap.base.passwd dc=foo,dc=com
ldap.enable on
ldap.minimum_bind_level simple
ldap.name cn=netapp,cn=users,dc=foo,dc=com
ldap.nssmap.attribute.gecos name
ldap.nssmap.attribute.gidNumber msSFU30GidNumber
ldap.nssmap.attribute.groupname cn
ldap.nssmap.attribute.homeDirectory msSFU30HomeDirectory
ldap.nssmap.attribute.loginShell msSFU30LoginShell
ldap.nssmap.attribute.memberNisNetgroup memberNisNetgroup
ldap.nssmap.attribute.memberUid memberUid
ldap.nssmap.attribute.netgroupname cn
ldap.nssmap.attribute.nisNetgroupTriple nisNetgroupTriple
ldap.nssmap.attribute.uid sAMAccountName
ldap.nssmap.attribute.uidNumber msSFU30UidNumber
ldap.nssmap.attribute.userPassword msSFU30Password
ldap.nssmap.objectClass.nisNetgroup nisNetgroup
ldap.nssmap.objectClass.posixAccount User
ldap.nssmap.objectClass.posixGroup Group
ldap.passwd ******
ldap.port 636
ldap.servers
ldap.servers.preferred
ldap.ssl.enable on
ldap.timeout 20
ldap.usermap.attribute.unixaccount sAMAccountName
ldap.usermap.attribute.windowsaccount sAMAccountName
ldap.usermap.base dc=foo,dc=com
ldap.usermap.enable on
Qual é a saída do seguinte comando? (esta é a minha saída)
nslookup
> set q=srv
_msdcs
Server: dc01.foo.com
Address: 10.17.0.1
_msdcs.foo.com
primary name server = dc01.foo.com
responsible mail addr = hostmaster
serial = 14628
refresh = 900 (15 mins)
retry = 600 (10 mins)
expire = 86400 (1 day)
default TTL = 3600 (1 hour)
> _ldap._tcp.dc._msdcs
(followed by a LOOONG list of posible servers :)