[Samba] Inconsistent SYSVOL ACLs

Anderson Sampaio Mello anderson.sampaio.mello at gmail.com
Sun Apr 2 23:53:58 UTC 2023


First of all thank you all for the answers and for trying to help me.

I agree with you michael regarding the parameters passed in the ./configure
command, the location is not part of the problem.

The file system used is XFS. and the strace command logs are in the
attached link
https://drive.google.com/file/d/1R_b6TzeJVmNIpnlkPfRk0CtkpeU4dgcg/view?usp=share_link

Rowland, the result of the command mentioned by you:

samba-tool ntacl get /usr/local/samba/var/lib/samba/sysvol --as-sddl

O:LAG:BAD:P(A;OICI;0x001f01ff;;;BA)(A;OICI;0x001200a9;;;SO)(A;OICI;0x001f01ff;;;SY)(A;OICI;0x001200a9;;;AU
)

Em dom., 2 de abr. de 2023 às 06:29, Rowland Penny via samba <
samba at lists.samba.org> escreveu:

>
>
> On 02/04/2023 09:21, Michael Tokarev via samba wrote:
>
> > Neither of the 3 should be a problem. Especially the ones which
> > are already set by default.  --enable-fhs uses slightly different
> > layout within $prefix, that's all. The build-time configuration
> > looks entirely okay.
>
> You may be correct Michael, but I still wouldn't use '--enable-fhs' by
> itself.
>
> >
> > There's something else going on here.
>
> Very probaby.
>
> >
> > Anderson, what filesystem the sysvol is on?
>
> This may be the cause, but it isn't being helped by Anderson using the
> wrong tool to check the permissions, he should be using samba-tool
> because this is a DC and the permissions are stored in an EA. I suggest
> he posts the output of:
>
> sudo samba-tool ntacl get /usr/local/samba/var/lib/samba/sysvol --as-sddl
>
> Rowland
>
>
>
> --
> To unsubscribe from this list go to the following URL and read the
> instructions:  https://lists.samba.org/mailman/options/samba
>


More information about the samba mailing list