[Samba] Enable_extended_ACL_support_in_smb.conf

Rowland penny rpenny at samba.org
Tue Jan 26 19:41:47 UTC 2016

On 26/01/16 19:24, Henry McLaughlin wrote:
> I am not 100% clear as to when the following is required in smb.conf on a
> member server:
>         vfs objects = acl_xattr
>         map acl inherit = yes
>         store dos attributes = yes
> https://wiki.samba.org/index.php/Shares_with_Windows_ACLs#Enable_extended_ACL_support_in_smb.conf
> I have confirmed Samba is compiled with ACL support:
> [root at centos7member ~]# smbd -b | grep HAVE_LIBACL
> [root at centos7member ~]#

I would have thought that was fairly obvious, you need the parameters on 
a domain member if you want to use extended ACLs i.e. if you want to set 
the ACLs from windows or with setfacl.
You do not need the parameters on a Samba AD DC, they are builtin.


More information about the samba mailing list