Group Memberships & ACL permissions?

Luke Kenneth Casson Leighton lkcl at
Thu Apr 16 14:57:56 GMT 1998

On Fri, 17 Apr 1998, Dana Canfield wrote:

> Sorry to bug everyone again.  Things are really starting to work well around
> here, but I have one more question.

you're not bugging anyone: you're asking the right questions.

>  Could someone tell me what NT groups you
> are a member of when validated by a Samba PDC.  I seem to have all sorts of
> problems when I try modifying the read/write permissions on the NT Workstation,
> even using Microsoft's own recommendations.  My only guess right now is that
> users validated over the PDC aren't getting to be members of the standard
> "users" group (though "everyone" doesn't seem to be working right, either).

ok, i have added a _temporary_ set of parameters

domain admin users =
domain guest users = 
domain groups = 

actually, the last one is a lie: it's local alias groups, and takes text
parameters or RID group numbers.  there are prior postings on this one.

> Also, if anyone has a good, general list of how permissions should be set on the
> directories to make a realtively secure, Samba-authenticated NT 4.0
> installation, I would be most appreciative.

at the moment, absolutely no idea.  don't forget that we haven't added any
code that maps between unix and NT groups, yet...


More information about the samba-ntdom mailing list