[Samba] Cannot set ACL rights for group "Authenticated Users" (SID S-1-5-11)\

Jeremy Allison jra at samba.org
Thu Apr 12 18:08:20 GMT 2007

On Thu, Apr 12, 2007 at 08:06:21PM +0200, Jens Nissen wrote:
> I cannot set rights on a arbitrary file or folder for the Windows
> predefined group "Authenticated Users" (which has SID S-1-5-11) via
> SAMBA 3.0.23d and the standard Windows 2000 File Attribute Dialog.
> Everything else works:
> - I can set rights for any other domain group.
> - I can read the ACL entry for "Authenticated Users" in the Windows 2000
> File Attribute Dialog if I set it manually with setfacl before
> - I am using tdbsam and the SID S-1-5-11 is mapped to GID 1018 (checked
> with "wbinfo -Y"), so SAMBA and Windows both seem to agree on the
> existence of this predefined group.
> What am I doing wrong? Is this supposed to work?
> Is there a workaround or any other suitable mapping for this group?
> In the "Unofficial Samba + ACL Howto", there is a reference (chapter
> 3.1.4) that this might not work, but that was back in 2003 and 4 years
> have passed since then.

What fails ? Selecting the user in the GUI ? More info on
exactly what isn't working would be good.


More information about the samba mailing list