[Samba] FreeBSD-11 and Samba-4.6 as a DC

Andrew Bartlett abartlet at samba.org
Mon Jul 17 09:32:43 UTC 2017


On Mon, 2017-07-17 at 19:18 +1000, Dewayne Geraghty wrote:
> Thanks for the pointer.  Yes it makes sense as there is no "security"
> namespace in FreeBSD and remapping the extended attribute into "user"
> namespace should work.

To be clear, that would not be safe.  I've commented on the bug.

I think we need those to be root-only, because we need to trust the
contents, as we sometimes override the underlying ACL based on the NT
ACL, to get semantics correct.

It is on the right track, but this one looks like it will take a little
longer. 

Sorry,

Andrew Bartlett

-- 
Andrew Bartlett                       http://samba.org/~abartlet/
Authentication Developer, Samba Team  http://samba.org
Samba Developer, Catalyst IT          http://catalyst.net.nz/services/samba




More information about the samba mailing list