Displaying 4 results from an estimated 4 matches for "acl3".
Did you mean:
acl
2024 Jan 31
2
Behavior of acl_xattr:ignore system acls = yes on a share
...'
> > was listed. I removed 'EVERYONE', clicked 'Apply' then 'OK', which
> > completed without error. 'EVERYONE' is no longer listed on Windows,
> > but if I go to the machine that holds the share and run 'samba-tool
> > ntacl get /srv/acl3 --as-sddl', I get this:
> >
> > O:S-1-22-1-0G:S-1-22-2-0D:AI(A;OICI;FA;;;S-1-22-1-0)(A;OICI;0x1200a9;;;DU)(A;OICI;0x1200a9;;;DU)(A;;FA;;;S-1-22-2-0)(A;;FA;;;S-1-22-2-0)(A;;FA;;;S-1-22-1-0)(A;;FA;;;WD)(A;OICIIO;FA;;;CO)(A;OICIIO;0x1200a9;;;S-1-22-2-0)(A;OICIIO;0x1200a9;;;CG)(A;OICII...
2024 Jan 31
1
Behavior of acl_xattr:ignore system acls = yes on a share
...d that 'EVERYONE' was
> listed. I removed 'EVERYONE', clicked 'Apply' then 'OK', which
> completed without error. 'EVERYONE' is no longer listed on Windows, but
> if I go to the machine that holds the share and run 'samba-tool ntacl
> get /srv/acl3 --as-sddl', I get this:
>
> O:S-1-22-1-0G:S-1-22-2-0D:AI(A;OICI;FA;;;S-1-22-1-0)(A;OICI;0x1200a9;;;DU)(A;OICI;0x1200a9;;;DU)(A;;FA;;;S-1-22-2-0)(A;;FA;;;S-1-22-2-0)(A;;FA;;;S-1-22-1-0)(A;;FA;;;WD)(A;OICIIO;FA;;;CO)(A;OICIIO;0x1200a9;;;S-1-22-2-0)(A;OICIIO;0x1200a9;;;CG)(A;OICIIO;0x1200a9...
2024 Jan 31
1
Behavior of acl_xattr:ignore system acls = yes on a share
...perties', I found that 'EVERYONE' was
listed. I removed 'EVERYONE', clicked 'Apply' then 'OK', which
completed without error. 'EVERYONE' is no longer listed on Windows, but
if I go to the machine that holds the share and run 'samba-tool ntacl
get /srv/acl3 --as-sddl', I get this:
O:S-1-22-1-0G:S-1-22-2-0D:AI(A;OICI;FA;;;S-1-22-1-0)(A;OICI;0x1200a9;;;DU)(A;OICI;0x1200a9;;;DU)(A;;FA;;;S-1-22-2-0)(A;;FA;;;S-1-22-2-0)(A;;FA;;;S-1-22-1-0)(A;;FA;;;WD)(A;OICIIO;FA;;;CO)(A;OICIIO;0x1200a9;;;S-1-22-2-0)(A;OICIIO;0x1200a9;;;CG)(A;OICIIO;0x1200a9;;;WD)
...
2024 Jan 31
2
Behavior of acl_xattr:ignore system acls = yes on a share
On 1/31/24 09:50, Peter Milesson via samba wrote:
> The crucial problem here is, that Everyone (yes, really everyone) can
> write to the root share.
why don't you just change it? That's how it's supposed to work.
-slow
--
SerNet Samba Team Lead https://samba.plus/
Samba Team Member https://samba.org/
SAMBA+ packages https://samba.plus/
SerNet