First off, apologies, I'm new to all this, learning a lot, but got a bit confused and need help unravellling it all. Am using 5.6 as a roaming domain controller, with fresh installs of xp on some machines (joined to domain) and a winxp box that was on a 2003 server, but is now part of the sme domain (called LOCAL just to be confusing. Will refer to Domain stuff as e.g. LOCAL\users local client computer as e.g local\users). Have done the controlset reg edits on all machines
As you may guesss I am getting confused about admin rights on the client machines. If I look in folder/ file security in windows xp, and do find users, there are LOCAL\Domain Users, Admins, Users etc. Looking in the memebers of Administrators groups, users Groups etc I can see linux-xxxxxxxx added to them suggesting that XP is recognising the Linux groups. When I try to add any of these LOCAL\groups to a security policy in XP (allow access to...) I can add users, but groups aren't recognised. strange non?
I can't see how to change users groups on my SME server, can make them (and wndows doesn't recognise these either), but surely there are domain user, user, admin groups that can be set- how? I know it's not a win server, but the fact that the linux-xxxxxxx shows in memberships seems to indicate they exist.
Do I have to create local users on every machine I want the LOCAL\USERS to use. Should they all be admins, best practice would say no, but at the moment it's the only way programs run. Would prefer to assign rights to LOCAL\USERS rahter than have to type in every user to every machine. The one that was on the win 2003 server can't run much unless I create a new account on the local machine
Maybe what I'm getting confused with is that SME server acts as authentication for logon, distribute the profile, but then windows won't use those server groups for security permissions. I'm a bit confused
I'll stop now as hopefully I can ask more questions and I'm sure someone will point me to a forum posting of howto I've missed. sorry for my ineptitude and rambling, I use Windows, but I'm trying
