question about privileges

Herb Lewis hlewis at
Sat Jun 25 22:29:30 MDT 2011

This happens when using the subinacl program to try to delete an acl on
a file.

Jeremy Allison wrote:
> On Fri, Jun 24, 2011 at 12:45:59PM -0700, Herb Lewis wrote:
>> When running samba 3.6.rc2 I am getting errors trying to change acls
>> on files on the samba share from an XP client. I notice that samba is
>> now looking at privileges and I get the following error
>> create_file_unixpath: open on testadmin.txt failed - SEC_FLAG_SYSTEM_SECURITY denied.
>> create_file_unixpath: NT_STATUS_PRIVILEGE_NOT_HELD
>> This didn't happen on my older version of samba because that piece of code
>> was in an #if 0. Where are these privileges set? Is this something I do
>> on the DC or something in samba?
> Does this happen on every ACL set ? It should only happen
> when the client is trying to set an audit ACL, which would
> only happen if the requested ACL contained one.
> Jeremy.

More information about the samba-technical mailing list