The problem is that it is possible but Samba is designed to offer
compatibility between a user accessing the tree via samba and the same
user accessing the tree under U*ix. Of course, Samba could be made to
support every (NT-)feature one can imagine, but it would not be possible
then to let a user logon to the Unix machine f.e. with telnet, because his
"rights" specified with the usual NT-admin-tools can not be mapped to unix
permissions. If these NT-ACLs would be implemented, they cannot be stored
in the file system (well, except for some special/new file systems) but
would have to be saved in some special database or in files all over the
directory tree or whatever. Since no unix tool would support using this
mechanism, the user would have either less or more access to his/other's
files, and that's not what Samba is designed for.

