[Samba] acl's and samba

Mahoney, Tom tom.mahoney at riaco.com
Fri Mar 15 15:27:03 GMT 2002


I asked a long winded question before about ACL's on linux with bestbits
patches and how everying in samba was essentially working but I couldn't
change modify or add acls' from a 2k workstation also on the domain.

Well I have a two part question.

Should I ((HAVE)) to add a map to /etc/samba/smbusers like:	user =
domain/user	?
My impression from reading the docs and peoples posts is that winbindd
should figure this out ALL ON IT'S OWN.
Is that not the case? In which case I'm SUPPOSED to add the map but it's
either not mentioned or vaguely implied?

Second.

With my homedir accessible ( only because I did add the map, and yes I know
that if I add the map and it works most people would just give me a blank
stare on this over my question above, but I want someone to please confirm
this for me. ) I can go to my home share and set and remove acl's but on my
file shares on the samba box I can't.
Ok, confirmed that kernel and samba support acls' and fileutils/e2fsprogs do
too.
Can set acls' from cli and view them with ls or getfacl and see them through
samba. Samba just can't change them. (except for home share)
Now seeing that it works with my home share I have to think that samba is
perfectly ready and willing to set them but it must be I assume a unix
permission problem.
Now currently ALL files and directories under the file shares have
permissions set like so:
chown -R root /home/samba/<all file share dirs>
chgrp -R domain/Domain Admins /home/samba/<all file share dirs>
chmod -R ugo+rwx /home/samba/<all file share firs>



More information about the samba mailing list