[Samba] Roaming profiles in domain level
Jeremy Allison
jra at samba.org
Sat Apr 30 08:48:10 GMT 2005
On Fri, Apr 29, 2005 at 07:20:49PM -0700, Li, Ying (ESG) wrote:
> I've finally found out how to use roaming profiles in domain level.
>
> Samba2.2 and 3.0 always checks owner's ACL for profile directories. But
> Samba returns correct owner ACL in a little bit different format with
> Windows. For example:
> Samba as profiles resource responses owner ACL for profile directory:
> Owner: S-1-5-21-2951980089-3660375505-290094901-1224
> Revision: 1
> Num Auth: 5
> Authority: 5
> Sub-authorities: 21-2951980089-3660375505-290094901
> RID: 1224
> Windows as profiles resource responses owner ACL for profile directory:
> Owner: S-1-5-21-2951980089
> Revision: 1
> Num Auth: 5
> Authority: 5
> Sub-authorities: 21-2951980089
>
> Even profile's owner is a valid domain user with accessible permissions
> on all files/directories in profile directory, Windows clients would
> disallow to access to profiles, and terminate to send incoming requests
> for loading profiles.
Can you send me an ethereal capture trace showing
this (from Windows). It looks very unusual to me.
Jeremy.
More information about the samba
mailing list