[PATCH] Re: The read ACL issues with Samba 4.0.0 (avoid need for acl:search=false)

Andrew Bartlett abartlet at samba.org
Sat Dec 29 16:36:49 MST 2012

On Sat, 2012-12-29 at 13:33 +0100, Marc Muehlfeld wrote:
> Am 29.12.2012 05:17, schrieb Andrew Bartlett:
> > If anybody who was having trouble with read ACLs, particularly anybody
> > who had to set 'acl:search=false' in the smb.conf could please try this
> > patch, and report results, it would be most helpful.
> I compiled your patch against 4.0.0.
> A non-domain-admin account is now seeing a bit more than before, but not as 
> much, as before rc6.

> But what I'm still missing for my nslcd is the attribute unixHomeDirectory. 
> This non-domain-admins (like my nslcd account) still can only see when I set 
> 'acl:search=false'.

This is interesting.  Indeed, we seem to have fixed the other basic
attributes, but not the unix attributes.

I'll keep searching. 


Andrew Bartlett

Andrew Bartlett                                http://samba.org/~abartlet/
Authentication Developer, Samba Team           http://samba.org

More information about the samba-technical mailing list