Samba4 Inheritance of directory ACLs

Lukasz Zalewski lukas at eecs.qmul.ac.uk
Fri Aug 31 03:02:42 MDT 2012


On 30/08/12 21:29, Marc Muehlfeld wrote:
> Hello,
>
> I played with delegation today, too. I wanted to allow a non-admin user
> to edit a group policy on an OU. But when I switched to this user, I
> could open the group policy, but when I made changes and clicked 'OK', I
> got 'access denied'. I even gave the user 'full access'.
>
> I did this with 4.0.0beta8-GIT-24356f3.

Hi Marc,
I have had limited success with delegation of privileges. Please see
https://bugzilla.samba.org/show_bug.cgi?id=8909

There are also other ACL releated bugs (listed in one of Metze's emails 
sent to the list few weeks ago).

However you should be able to delegate full access - do note that if you 
already have existing objects in that container, you will have to 
propagate the privileges youself.
Newly created object will inherit those delegated privileges correctly 
though.

Regards

L


More information about the samba-technical mailing list