[Samba] Fileserver and access groups

Rowland Penny rowlandpenny at googlemail.com
Mon Mar 30 11:09:22 MDT 2015


On 30/03/15 18:00, jd at ionica.lv wrote:
> Hi!
>
> I have Samba AD DC and Samba fileserver (hereafter-FS) as domain 
> member. I need to organize access to the specific shares on FS for a 
> groups of specific domain users. Where should I make the domain user 
> groups - on DC, on FS or on both?
>
> Does the FS need any local Samba users at all? What if domain users' 
> homes are located on FS?
>
> Janis
>

All your users & groups should be stored in AD, except for users like 
'root' (yes korashi I am looking at you) or www-data, ntp etc i.e. any 
user or group that has an ID less than 1000.

You use ACLs for users homes stored on the fileserver, the fileserver 
needs to be joined to the domain.

Rowland


More information about the samba mailing list