Questions about ACLs

Andrew Bartlett abartlet at samba.org
Wed May 30 00:31:25 MDT 2012


On Wed, 2012-05-30 at 08:20 +0200, Marc Muehlfeld wrote:
> Am 30.05.2012 08:08, schrieb Andrew Bartlett:
> > If you were using a version before alpha21, then s3fs wasn't the
> > default, and so we didn't attempt to emulate the NT ACL into a POSIX
> > ACL.
> 
> I used the latest git version from yesterday (4.0.0alpha22-GIT-9102ccf). I 
> used the following command for the migration:
> # /usr/local/samba/bin/samba-tool domain samba3upgrade 
> --dbdir=/usr/var/locks3/ --use-xattrs=yes --realm=MUC.medizinische-genetik.de 
> /etc/samba/smb3.conf
> 
> 
> When I add
> server services = -smb +s3fs
> dcerpc endpoint servers = -winreg -srvsvc
> to my smb.conf, it is stored in the filesystem.

Great.

> >> And one more question about ACLs:
> >> In my s3 live system, my user/groups are stored in LDAP and I see the
> >> owner/group of file trough nss_ldap on linux. In my s4 test environment, now
> >> all files show only the uid/gid on files/directories. Can I get the
> >> user-/groupnames back by letting nss_ldap connect to the samba LDAP?
> >
> > Use nss_winbind for that.
> 
> Do user/groups have the same IDs than before the migration from LDAP trough 
> winbind.

Yes, they do.

Andrew Bartlett

-- 
Andrew Bartlett                                http://samba.org/~abartlet/
Authentication Developer, Samba Team           http://samba.org



More information about the samba-technical mailing list