Proposal to remove confusing "security XX mask" parameters for 4.0.0

Jeremy Allison jra at
Wed Oct 3 14:29:53 MDT 2012

On Wed, Oct 03, 2012 at 02:57:14PM -0500, Ricky Nance wrote:
> >From my stand point, these options are more confusing than helpful. Users
> coming from Samba 3 often try to specify these options AND try to use the
> 'Windows security settings'. Just last week a user had issues related to
> setting these and not getting the outcome they expected. I had them remove
> everything from the share definition except the path and 'read only = no'
> options and set it though windows and they were  quite pleased when things
> worked as expected. In my opinion these options were put in an old system
> to make up for the things it lacked (at the time), and it would show
> progression to remove them and make it work for "todays" systems. Please
> don't misunderstand me these were great with Samba 3, but from a users
> standpoint its MUCH easier to use ACL's.

Ok, I'm glad to head this.

But this does bring up one more important thing.

Currently the default setting for "create mask = 0744" and
"directory mask = 0755".

If we're really going to recommend ACLs forever from
now on we should probably change these to 0777 as
a default.


More information about the samba-technical mailing list