[Samba] using Windows AD unwanted Group rights get applied to new Files

Rowland Penny rpenny at samba.org
Tue Aug 7 07:57:02 UTC 2018


On Mon, 6 Aug 2018 21:27:41 +0000
VELARTIS Philipp Dürhammer via samba <samba at lists.samba.org> wrote:

> Hi,
> 
> we have some Samba shares joined a existing Windows AD.
> Everything works well with complex user rights.
> But the problem ist that when a user creates a new file the standard
> windows group (domain-user) is also applied as a permission to the
> file. This breaks all the security because all users have now full
> acess to this file. (because all users are in the domain-user group)
> All parent directories do not have this permission set. Where does it
> come from?
> 
> Thank you

It comes from the user ;-)

What OS ?

What Samba version ?

Can you post your smb.conf

Rowland



More information about the samba mailing list