[Samba] 4.15 windows ACL share. Not taking?

spindles seven spindles7 at gmail.com
Wed Mar 2 18:40:20 UTC 2022


On 02 March 2022 17:05 Rowland Penny wrote:
> On Wed, 2022-03-02 at 16:48 +0000, spindles seven via samba wrote:
> > On 02 March 2022 13:33 Rowland Penny wrote:
> > > On Wed, 2022-03-02 at 09:39 +0000, Manu Baylac via samba wrote:
> > > > Le 28/02/2022   20:26, Rowland Penny via samba a  crit :
> 
> I feel that this must be an artefact of the recent CVE updates, I have never used that
> line myself, but Louis has, so presumably it did work at some point. What I can say is
> that if you set 'acl_xattr:ignore system acls = yes' on share when using Samba
> 4.15.5 , then that share does not get extended NT ACLS (no '+' sign at end of Unix
> acls) when permissions are set from Windows.
> 
Ok that may explain it, but I just did a test with a new share on a member server running Samba 4.15.5
and found that I still get the + after setting the ACLs from Windows and can still use it after adding the
'acl_xattr:ignore system acls = yes' to the share definition.    Do you have to use a brand-new server running
Samba version  4.15.5 rather than one that has been upgraded?

Roy




More information about the samba mailing list