[Samba] Samba 4.1 + User Homes

spamvoll at googlemail.com spamvoll at googlemail.com
Sat Oct 26 13:01:34 MDT 2013


Hi Marc,

if never heard of getfacl :)
FS is XFS

# getfacl /home/HOME/bspears/
getfacl: Removing leading '/' from absolute path names
# file: home/HOME/bspears/
# owner: 3000000
# group: users
# flags: -s-
user::rwx
user:root:rwx
group::rwx
group:users:rwx
group:3000000:rwx
group:3000022:rwx
mask::rwx
other::---
default:user::rwx
default:user:root:rwx
default:user:3000000:rwx
default:group::rwx
default:group:users:rwx
default:group:3000000:rwx
default:group:3000022:rwx
default:mask::rwx
default:other::---

# getfacl /home/Profiles/bspears.V2/
getfacl: Removing leading '/' from absolute path names
# file: home/Profiles/bspears.V2/
# owner: 3000022
# group: users
user::rwx
group::---
group:users:---
group:3000002:rwx
group:3000022:rwx
mask::rwx
other::---
default:user::rwx
default:user:3000022:rwx
default:group::---
default:group:users:---
default:group:3000002:rwx
default:group:3000022:rwx
default:mask::rwx
default:other::---



2013/10/26 Marc Muehlfeld <samba at marc-muehlfeld.de>

> Am 26.10.2013 18:15, schrieb spamvoll at googlemail.com:
>
>  Profiles which are working have the following pems:
>> drwxrwx---+ 14 3000022 users 4096 Okt 26 17:37 bspears.V2
>> drwxrwx---+ 14 3000019 users 4096 Okt 26 17:34 testuser.V2
>>
>> Homes have:
>> drwxrws---+  4 3000000 users   36 Okt 26 17:38 bspears
>> drwxrws---+  2 3000000 users   35 Okt 26 17:34 testuser
>>
>
>
> Do you see the "+" on the permissions? This indicates, that there are
> extended ACLs on that file/directory (not only for owner/group/other).
>
> What does a "getfacl" on a users home and profile folder show? I guess,
> there are extended ACLs that allow the additional access.
>
>
> Regards,
> Marc
>
>
>


More information about the samba mailing list