[Samba] Roaming profiles in domain level

Jeremy Allison jra at samba.org
Sat Apr 30 08:48:10 GMT 2005


On Fri, Apr 29, 2005 at 07:20:49PM -0700, Li, Ying (ESG) wrote:
> I've finally found out how to use roaming profiles in domain level.
> 
> Samba2.2 and 3.0 always checks owner's ACL for profile directories. But
> Samba returns correct owner ACL in a little bit different format with
> Windows. For example:
> Samba as profiles resource responses owner ACL for profile directory:
>   Owner: S-1-5-21-2951980089-3660375505-290094901-1224
>      Revision: 1
>      Num Auth: 5
>      Authority: 5
>      Sub-authorities: 21-2951980089-3660375505-290094901
>      RID: 1224
> Windows as profiles resource responses owner ACL for profile directory:
>   Owner: S-1-5-21-2951980089
>      Revision: 1
>      Num Auth: 5
>      Authority: 5
>      Sub-authorities: 21-2951980089
> 
> Even profile's owner is a valid domain user with accessible permissions
> on all files/directories in profile directory, Windows clients would
> disallow to access to profiles, and terminate to send incoming requests
> for loading profiles. 

Can you send me an ethereal capture trace showing
this (from Windows). It looks very unusual to me.

Jeremy.


More information about the samba mailing list