[Samba] book of samba 4.1 or 4.2

Rowland Penny rpenny at samba.org
Thu Nov 17 20:19:27 UTC 2016

On Thu, 17 Nov 2016 20:07:26 +0000
Alex Crow via samba <samba at lists.samba.org> wrote:

> On 17/11/16 19:48, Rowland Penny via samba wrote:
> > If you are running Samba as an AD DC or domain member, then you
> > shouldn't be using 'valid' & 'invalid' any more. As for creating
> > users etc, samba-tool comes with help, try running 'samba-tool
> > --help'
> >
> > If you have more questions, please feel free to ask ;-)
> >
> > Rowland
> >
> What? Really? "valid users" and "invalid users" doesn't work on a
> Samba 4 AD member?

Just where did I say 'doesn't' ???

I said 'shouldn't', you should use ACL's instead, either by setting the
permissions from windows or with setfacl
> We reply on this for shares that have other shares below them (Posix
> ACLs only). Where is it documented that this is now not functional?

It is still functional, but is the old way of doing things, if you are
using them, carry on, but there are better ways of doing it now.

> I'm hoping it just means it's deprecated and some other mechanism has
> supplanted it, in which case I'd like to know how to restrict at the
> share level properly!

Try reading this:



More information about the samba mailing list