Hello all, I try to set full control permission to a "Boss" directory for one group and in the same time I want to prevent this group to erase this top directory. Is it possible to do that with different permission in the Boss parent directory? Here is a small draw for explain : For the moment I can't prevent a user member of Boss group to delete Boss directory... Thanks for helping Sam
ACL should be apply-able on the object, the object and its children or on children only. Apply full control ACL for children only and for the folder itself MS should have something to allow content modification only... 2016-08-30 16:16 GMT+02:00 Sam via samba <samba at lists.samba.org>:> Hello all, > > I try to set full control permission to a "Boss" directory for one group > and in the same time I want to prevent this group to erase this top > directory. > > Is it possible to do that with different permission in the Boss parent > directory? > Here is a small draw for explain : > > For the moment I can't prevent a user member of Boss group to delete Boss > directory... > Thanks for helping > > Sam > > -- > To unsubscribe from this list go to the following URL and read the > instructions: https://lists.samba.org/mailman/options/samba >
Hello Mathias, All Works but only for the content of the boss directory. I have well identicate the "apply To" option with the 3 possibility ( this folder only, subfolders, files ), but I can't prevent deleting boss folder with settings permission on this folder. The only way I see to make it possible is to set boss parent directory permission with read only, that makes all directorys in the same level with read only permission too... Sam Le 30/08/2016 à 16:38, mathias dufresne a écrit :> ACL should be apply-able on the object, the object and its children or > on children only. > > Apply full control ACL for children only and for the folder itself MS > should have something to allow content modification only... > > 2016-08-30 16:16 GMT+02:00 Sam via samba <samba at lists.samba.org > <mailto:samba at lists.samba.org>>: > > Hello all, > > I try to set full control permission to a "Boss" directory for one > group and in the same time I want to prevent this group to erase > this top directory. > > Is it possible to do that with different permission in the Boss > parent directory? > Here is a small draw for explain : > > For the moment I can't prevent a user member of Boss group to > delete Boss directory... > Thanks for helping > > Sam > > -- > To unsubscribe from this list go to the following URL and read the > instructions: https://lists.samba.org/mailman/options/samba > <https://lists.samba.org/mailman/options/samba> > >
Ok so If I well understand the concept, ACL should be apply-able _on_ the object himself only from the parent object? For instance : if I want read attribute on a directory I have to set it on the parent directory. And if I want read attribute inside a directory, I can set it on the directory. Hope this instance is clear to understand... Thanks for confirm me that. ;) Samuel Le 30/08/2016 à 16:38, mathias dufresne a écrit :> ACL should be apply-able on the object, the object and its children or > on children only. > > Apply full control ACL for children only and for the folder itself MS > should have something to allow content modification only... > > 2016-08-30 16:16 GMT+02:00 Sam via samba <samba at lists.samba.org > <mailto:samba at lists.samba.org>>: > > Hello all, > > I try to set full control permission to a "Boss" directory for one > group and in the same time I want to prevent this group to erase > this top directory. > > Is it possible to do that with different permission in the Boss > parent directory? > Here is a small draw for explain : > > For the moment I can't prevent a user member of Boss group to > delete Boss directory... > Thanks for helping > > Sam > > -- > To unsubscribe from this list go to the following URL and read the > instructions: https://lists.samba.org/mailman/options/samba > <https://lists.samba.org/mailman/options/samba> > >