Windows 2012r2/Windows8 Security Advanced tab throws caution banner "Unable to contact Active Directory to access or verify claim type"

Jeremy Allison jra at samba.org
Tue Feb 9 21:17:34 UTC 2016


On Mon, Feb 08, 2016 at 10:26:07PM -0800, Partha Sarathi wrote:
> Hi Folks,
> 
> We use samba-4.1.19 version and noticed a caution banner "Unable to contact
> Active Directory to access or verify claim type" while adding a ACL from
> advanced security tab against windows 2012r2/windows10 client.
> 
> Tested the same scenario  against windows-2012r2 share and we don't see
> this caution banner.
> 
> attached the screenshot for reference.
> 
> The below link refers how to enable and use the claim type access.
> 
> http://windowsitpro.com/windows-server-2012/enable-claims-support-windows-server-2012-active-directory
> 
> Is this claim based access is considered/supports in SAMBA Security
> Descriptor.?

No, we don't currently support claims-based ACLs.

You are the first customer to even mention it :-).

We would need to do some work on the ACL storage
and evaluation engine to make this work.

Jeremy.



More information about the samba-technical mailing list