NO_PROPOGATE_INHERIT_ACE in nt acls

Gerald Carter jerry at samba.org
Mon Jan 21 10:22:03 GMT 2002


On Fri, 18 Jan 2002, Georgina Russell wrote:

>
> I've been reading through the source and I don't see the
> NO_PROPOGATE_INHERIT_ACE flag being checked when unpacking security
> descriptors. However, I do see a #define for it.  Do you plan to support
> this in the future?  What is the reason for leaving this out?

I'll leave this one to Jeremy....

> Also, I'm having a hard time figuring out how SACL's are supported.
> It doesn't seem like they are stored on disk.  Is this correct?

Yes.  That it correct.  We map the DACL to a POSIX ACL.
IMO The correct solution would be to modify Samba's VFS to
pass the security descriptor to the file system and let it
through it away (assuming it doesn't care about it).






chau, jerry
 ---------------------------------------------------------------------
 Hewlett-Packard                                     http://www.hp.com
 SAMBA Team                                       http://www.samba.org
 --                                            http://www.plainjoe.org
 "Sam's Teach Yourself Samba in 24 Hours" 2ed.      ISBN 0-672-32269-2
 --"I never saved anything for the swim back." Ethan Hawk in Gattaca--





More information about the samba-technical mailing list