[Samba] Re: file permission problem
Justin Georgeson
jgeorgeson at unboundtech.com
Thu Oct 3 01:39:00 GMT 2002
Okay, I installed the 2.2.5 RPM. I used testparm to get a complete
listing of my smb.conf, and have attached it. All client machines are
Win 2k, I believe they are all at service pack 3, but I know for certain
the one I was just testing on is. I can log in as my domain account, my
profile is downloaded. I go to My Network Places, I see the Add icon,
and the Entire Network icon. I expect to see a list of machines in the
domain, is there some configuration I'm missing, on either client or
server? I go to the Public share, I can create files/folders. I
right-click, go to Properties, select the Security tab, and am unable to
change the settings. For example, if I change the permissions allowed to
the owning group and hit apply, the changes just undo themselves. If I
try to add a user/group, when I hit apply, I get an error dialog that says
"Unable to save permission changes on <folder/file name>."
"Access is denied."
It would appear, from the NT Properties/Security dialog, that the owner
has full control, and the group/everyone have no access. I would have
thought I, through the create [directory] mask setting, given rwx
permission to the group. That is how I have set the unix permissions on
the samba server (by hand, after the files/folders were created). I read
somewhere to setgid on folders so that subfolders and files will have
the same group. I log off, my profile is synched back up with the samba
server.
So I can't change file/folder permissions and I can't browse the domain
without going to Entire Network->Microsoft Windows Network->Unboundtech.
Is it necessary for the netlogon share to be browseable?
Bradley W. Langhorst wrote:
> 2.2.1 is very old and has lots of bugs...
> upgrade to 2.2.6 when that comes out this week
> (or if you cant wait use 2.2.5)
>
> On Wed, 2002-10-02 at 11:37, Justin Georgeson wrote:
>
>>Does anyone have any suggestions here? I've read plenty of documentation
>>and can't figure this out (HOWTOs and man pages). I'm apparently also
>>having a problem with profiles synching back up the server. Users are
>>apparently looisng work. This is bad. I *know* this product can work for
>>me, but I'm not having much luck. Please help.
>
>
>>>[export0]
>>> path = /export0
>>> write list = @unboundtech
>>> read only = No
>>
> this should be yes - otherwise everybody can write.
>
>
>>> create mask = 0775
>>> directory mask = 0775
>>
>
> have you enable acls on the server's filesystem? It sounds like that is
> what you want...
>
> brad
>
--
Justin Georgeson
UnBound Technologies, Inc.
http://www.unboundtech.com
Main 713.329.9330
Fax 713.460.4051
Mobile 512.789.1962
5295 Hollister Road
Houston, TX 77040
Real Applications using Real Wireless Intelligence(tm)
-------------- next part --------------
Load smb config files from /etc/samba/smb.conf
Processing section "[netlogon]"
Processing section "[profiles]"
Processing section "[Public]"
Loaded services file OK.
Press enter to see a dump of your service definitions
# Global parameters
[global]
coding system =
client code page = 850
code page directory = /etc/codepages
workgroup = UNBOUNDTECH
netbios name = MOLEHILL
netbios aliases =
netbios scope =
server string = Domain Controller
interfaces = lo 192.168.1.0/24
bind interfaces only = Yes
security = USER
encrypt passwords = Yes
update encrypted = No
allow trusted domains = Yes
hosts equiv =
min passwd length = 5
map to guest = Never
null passwords = No
obey pam restrictions = No
password server =
smb passwd file = /etc/samba/smbpasswd
root directory =
pam password change = No
passwd program = /usr/bin/passwd
passwd chat = *new*password* %n\n *new*password* %n\n *changed*
passwd chat debug = No
username map =
password level = 0
username level = 0
unix password sync = No
restrict anonymous = No
lanman auth = Yes
use rhosts = No
admin log = No
log level = 0
syslog = 1
syslog only = No
log file = /var/log/samba/log.%m
max log size = 50
timestamp logs = Yes
debug hires timestamp = No
debug pid = No
debug uid = No
protocol = NT1
large readwrite = No
max protocol = NT1
min protocol = CORE
read bmpx = No
read raw = Yes
write raw = Yes
nt smb support = Yes
nt pipe support = Yes
nt status support = Yes
announce version = 4.5
announce as = NT
max mux = 50
max xmit = 65535
name resolve order = lmhosts host wins bcast
max packet = 65535
max ttl = 259200
max wins ttl = 518400
min wins ttl = 21600
time server = No
unix extensions = No
change notify timeout = 60
deadtime = 0
getwd cache = Yes
keepalive = 300
lpq cache time = 10
max smbd processes = 0
max disk size = 0
max open files = 10000
read size = 16384
socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
stat cache size = 50
use mmap = Yes
total print jobs = 0
load printers = Yes
printcap name = /etc/printcap
disable spoolss = No
enumports command =
addprinter command =
deleteprinter command =
show add printer wizard = Yes
os2 driver map =
strip dot = No
mangling method = hash
character set =
mangled stack = 50
stat cache = Yes
domain admin group = @domainadmin
domain guest group =
machine password timeout = 604800
add user script = /usr/sbin/useradd -d /dev/null -g 100 -s /bin/false -M %u
delete user script =
logon script =
logon path = \\%N\profiles\%U
logon drive = Z:
logon home = \\%N\profiles\%U
domain logons = Yes
os level = 34
lm announce = Auto
lm interval = 60
preferred master = True
local master = Yes
domain master = True
browse list = Yes
enhanced browsing = No
dns proxy = No
wins proxy = No
wins server =
wins support = Yes
wins hook =
kernel oplocks = Yes
lock spin count = 3
lock spin time = 10
oplock break wait time = 0
add share command =
change share command =
delete share command =
config file =
preload =
lock dir = /var/cache/samba
pid directory = /var/run/samba
utmp directory =
wtmp directory =
utmp = No
default service =
message command =
dfree command =
valid chars =
remote announce =
remote browse sync =
socket address = 0.0.0.0
homedir map =
time offset = 0
NIS homedir = No
source environment =
panic action =
hide local users = No
host msdfs = No
winbind uid =
winbind gid =
template homedir = /home/%D/%U
template shell = /bin/false
winbind separator = \
winbind cache time = 15
winbind enum users = Yes
winbind enum groups = Yes
winbind use default domain = No
comment =
path =
alternate permissions = No
username =
guest account = nobody
invalid users =
valid users =
admin users =
read list =
write list =
printer admin =
force user =
force group =
read only = Yes
create mask = 0775
force create mode = 00
security mask = 0777
force security mode = 00
directory mask = 0775
force directory mode = 00
directory security mask = 0777
force directory security mode = 00
force unknown acl user = 00
inherit permissions = No
inherit acls = No
guest only = No
guest ok = No
only user = No
hosts allow =
hosts deny =
status = Yes
nt acl support = Yes
block size = 1024
max connections = 0
min print space = 0
strict allocate = No
strict sync = No
sync always = No
write cache size = 0
max print jobs = 1000
printable = No
postscript = No
printing = bsd
print command = lpr -r -P%p %s
lpq command = lpq -P%p
lprm command = lprm -P%p %j
lppause command =
lpresume command =
queuepause command =
queueresume command =
printer name =
use client driver = No
default devmode = No
printer driver =
printer driver file = /etc/samba/printers.def
printer driver location =
default case = lower
case sensitive = No
preserve case = Yes
short preserve case = Yes
mangle case = No
mangling char = ~
hide dot files = Yes
hide unreadable = No
delete veto files = No
veto files =
hide files =
veto oplock files =
map system = No
map hidden = No
map archive = Yes
mangled names = Yes
mangled map =
browseable = Yes
blocking locks = Yes
csc policy = manual
fake oplocks = No
locking = Yes
oplocks = Yes
level2 oplocks = Yes
oplock contention limit = 2
posix locking = Yes
strict locking = No
share modes = Yes
copy =
include =
exec =
preexec close = No
postexec =
root preexec =
root preexec close = No
root postexec =
available = Yes
volume =
fstype = NTFS
set directory = No
wide links = Yes
follow symlinks = Yes
dont descend =
magic script =
magic output =
delete readonly = No
dos filemode = No
dos filetimes = No
dos filetime resolution = No
fake directory create times = No
vfs object =
vfs options =
msdfs root = No
[netlogon]
path = /usr/share/samba/netlogon
write list = @domainadmin
[profiles]
path = /home/profiles
read only = No
inherit permissions = Yes
inherit acls = Yes
[Public]
path = /export0
read only = No
inherit permissions = Yes
inherit acls = Yes
More information about the samba
mailing list