[Samba] Re: group profiles

John H Terpstra jht at samba.org
Wed Apr 30 13:32:56 GMT 2008


On Wednesday 30 April 2008 08:14:17 am Andreas Moroder wrote:
> Hello John,
>
> > You can name the profile anything you want, so long as the ACLs inside
> > the profile are correct for the group that needs to be able to access it.
> >
> > As a general rule, the ACLs should be set so that members of the group
> > have full control.  Then select a user who is a member of that group; set
> > the profile path to the new group profile; now log on as that user and
> > edit, or clean up and polish up the setting for that profile.  Now log
> > off. As the Domain Admin rename the user.dat file to user.man.
> >
> > You now have a "mandatory" (meaning - usr can not change the profile
> > settings) profile that is accessible only by members of the group.
>
> Now I know how to prepare the mandatory profile.
>
> > Group members will be able to access this group profile - but first the
> > administrator must set their profile path to point to this group profile.
>
> Does this mean, that they have only this profile or is it possible to
> have a mandatory group profile and a personal profile ?

I am not aware of any way to implement mulitple additive profiles in Windows 
NT4 domain structures.

> > Does that clarify things?
> >
> > - John T.
>
> Maybe I oversought this in the howto, but your explanation should be
> added to the howto.

I'll review that some time.

Cheers,
John T.


More information about the samba mailing list