search for: cifsacl

Displaying 20 results from an estimated 29 matches for "cifsacl".

2020 Sep 24
4
cifsacl not working
...case AD is down). All other user/group accounts are >= 1001 and come from the AD. Technically that line should probably be 1001-29999, but not sure if that would impact user 1001. The only user in my /etc/passwd is local:x:1000:1000:local,,,:/home/local:/bin/bash > > You are using 'cifsacls' and this calculates a 32 bit ID from the SID, > so it is unlikely your users are getting the same ID from Samba and > cifsacls, I get the feeling that you use one or the other, not both :-\ > Can you please expand on this, I am confused as to what you are suggesting.? If 'get...
2020 Sep 25
2
cifsacl not working
...ur?lien Aptel via samba wrote: > Ken Bass via samba <samba at lists.samba.org> writes: >> Can you please expand on this, I am confused as to what you are >> suggesting.? If 'getent pass' works properly and shows no >> overlap/confusion, this seems to be related to cifsacl. > It's still hard to say at this point. > > cifs.idmap logs messages in the syslog. > Can you try mounting with cifsacl, then look at logs in one window > > # journalctl --since=now > > While you do a > > # ls -l /path/to/cifsaclmount/some_file > > If a mapp...
2020 Sep 24
2
cifsacl not working
...;> >>> Cheers, >> >> # wbinfo -i MYDOM\\user >> user:*:1001:1001::/home/user:/bin/bash >> >> Those uid/gid are correct. They match the server and also match the >> uid/gid in the AD for the user. >> It seems everything is working except for the cifsacl id mapping part. > > I am beginning to think you are running Samba as a standalone server > in an AD domain, if so, why ? > > As I said, posting your smb.conf will prove this. > > Rowland > > > I already did that, two posts ago. Did it not make it to the list - I see...
2011 Sep 23
0
ANNOUNCE: cifs-utils release 5.1 available for download
...#39;ve had a number of changes since the last release, and we have some other upcoming kernel changes that might require corresponding cifs-utils changes. So it's probably as good a time as any for a new release. Highlights: + fix for a minor security issue that can corrupt the mtab + new getcifsacl/setcifsacl tools that allow you to fetch and set raw Windows ACLs via an xattr. + a lot of manpage patches webpage: http://linux-cifs.samba.org/cifs-utils/ tarball: ftp://ftp.samba.org/pub/linux-cifs/cifs-utils/ git: git://git.samba.org/cifs-utils.git gitweb: http://git.samba.o...
2020 Sep 24
2
cifsacl not working
...^^^^^ ^^^^^ > uid gid > > Cheers, # wbinfo -i MYDOM\\user user:*:1001:1001::/home/user:/bin/bash Those uid/gid are correct. They match the server and also match the uid/gid in the AD for the user. It seems everything is working except for the cifsacl id mapping part.
2020 Sep 24
0
cifsacl not working
...gt;>> >>> # wbinfo -i MYDOM\\user >>> user:*:1001:1001::/home/user:/bin/bash >>> >>> Those uid/gid are correct. They match the server and also match the >>> uid/gid in the AD for the user. >>> It seems everything is working except for the cifsacl id mapping part. >> >> I am beginning to think you are running Samba as a standalone server >> in an AD domain, if so, why ? >> >> As I said, posting your smb.conf will prove this. >> >> Rowland >> >> >> > I already did that, two posts...
2020 Sep 25
2
cifsacl not working
...5:14 AM, Aur?lien Aptel wrote: > Ken Bass via samba <samba at lists.samba.org> writes: >> Can you please expand on this, I am confused as to what you are >> suggesting.? If 'getent pass' works properly and shows no >> overlap/confusion, this seems to be related to cifsacl. > It's still hard to say at this point. > > cifs.idmap logs messages in the syslog. > Can you try mounting with cifsacl, then look at logs in one window > > # journalctl --since=now > > While you do a > > # ls -l /path/to/cifsaclmount/some_file > > If a mapp...
2020 Sep 26
1
cifsacl not working - RESOLVED
...utils package installs /etc/request-key.d/cifs.idmap.conf /etc/request-key.d/cifs.spnego.conf However the package only has a 'suggestion' of the keyutils package. Without installing keyutils which creates the /etc/request-key.conf file AND installed the /sbin/request-key binary, the 'cifsacl' option doesn't work / perform the winbind mapping as it should. Thanks Aur?lien and Rowland for your help.
2020 Sep 25
0
cifsacl not working
Ken Bass via samba <samba at lists.samba.org> writes: > Can you please expand on this, I am confused as to what you are > suggesting.? If 'getent pass' works properly and shows no > overlap/confusion, this seems to be related to cifsacl. It's still hard to say at this point. cifs.idmap logs messages in the syslog. Can you try mounting with cifsacl, then look at logs in one window # journalctl --since=now While you do a # ls -l /path/to/cifsaclmount/some_file If a mapping fails you should see something like this: cifs.id...
2020 Sep 25
0
cifsacl not working
Rowland penny via samba <samba at lists.samba.org> writes: > 'S-1-5-18' is SYSTEM and from the looks of it, neither cifs.idmap or > winbind maps it on a Unix domain member (it does map on a Samba DC). It > is hard to understand from the manpages, does cifsacls use the same ID's > as Winbind, or does it calculate its own ? * cifsacl is the mount option. * When passed, it makes cifs.ko call the userspace program cifs.idmap everytime it has to map a SID. * cifs.idmap has a winbind or sssd backend (dynamicly loaded librairies aka plugins). * Th...
2020 Sep 25
0
cifsacl not working
...n Aptel wrote: >> Ken Bass via samba <samba at lists.samba.org> writes: >>> Can you please expand on this, I am confused as to what you are >>> suggesting.? If 'getent pass' works properly and shows no >>> overlap/confusion, this seems to be related to cifsacl. >> It's still hard to say at this point. >> >> cifs.idmap logs messages in the syslog. >> Can you try mounting with cifsacl, then look at logs in one window >> >> # journalctl --since=now >> >> While you do a >> >> # ls -l /path/to/ci...
2020 Sep 25
1
cifsacl not working
...gt;>> Ken Bass via samba <samba at lists.samba.org> writes: >>>> Can you please expand on this, I am confused as to what you are >>>> suggesting.? If 'getent pass' works properly and shows no >>>> overlap/confusion, this seems to be related to cifsacl. >>> It's still hard to say at this point. >>> >>> cifs.idmap logs messages in the syslog. >>> Can you try mounting with cifsacl, then look at logs in one window >>> >>> # journalctl --since=now >>> >>> While you do a >&...
2014 Mar 25
0
Behavior of cifsacl
...rom some RPMs I found on Glusterfs's site of all places), and voila! She authenticates! But, sadly, I realized at that point (because my cifs mounts failed) that the samba4-* packages don't provide cifs.mount... So I grabbed a tarball of cifs-utils 6.3, installed the deps for building the cifsacl stuff, built and installed it. Now my shares mount up. With some quick-n-dirty testing, though, it doesn't seem like groups added to the Windows security ACL are being respected on the Linux side. Am I asking too much, or is this something that can actually be done? If it is actually possib...
2020 Sep 24
2
cifsacl not working
On 9/24/20 8:53 AM, Aur?lien Aptel wrote: > Ken Bass via samba <samba at lists.samba.org> writes: >> I installed a new Ubuntu 20.4 LTS system (smbd 4.11.6) . Initially I >> tried using the SSSD and 'realm' to join the domain. Everything worked >> similar to my Centos 7 install and I thought I was finished. >> >> The one thing not working is? cifs
2020 Sep 24
4
cifsacl not working
...ping. Based on some online posts, including from Rowland, I got rid of SSSD and configured samba/winbind only. Lots of posts saying 'winbind is not sssd'. Still doesn't work. In both cases, 1) The mounted share mount -t cifs //192.168.1.1/test /mnt/test -odomain=TESTDOM,sec=ntlmssp,cifsacl,credentials=xzy shows all files owned by root/root rather than the domain users. 2) If I run getcifsacl /mnt/test it shows the proper named windows ACL as expected 3) /usr/lib/x86_64-linux-gnu/cifs-utils/idmapwb.so is setup as the /etc/cifs-utils/idmap-plugin I've been messing with this f...
2017 Nov 09
1
Windows server 2003 domain authentication with Samba version 4.7.0-git.23.4e3f0fb9d15SUSE-oS13.3-x86_64
...E-oS13.3-x86_64 in openSUSE Tumbleweed can not authentificate me on Windows server 2003 domain in /etc/fstab I have working combination - smb version only vorks if set to 1.0 //192.168.1.131/shares /home/fodrek/shares cifs credentials=/home/fodrek/ cifs.creds,iocharset=utf8,sec=ntlm,cifsacl,user,nosuid,uid=fodrek,gid=users,vers=1.0 0 0 On tyhe server I am detected as operating system Name:openSUSE Tumbleweed version: 20171104 Service pack: 4.7.0-git.23.4e3f0fb9d15SUSE-oS13.3-x86_64 Is it possible to help me with allowing to authentificate me into domain,please? I look forward...
2019 Oct 25
1
net ads join -- strange message
...ptions allow="nosuid,nodev,loop,encryption,fsck" /> <mntoptions require="nosuid,nodev" /> <lsof>/usr/bin/lsof %(MNTPT) </lsof> <cifsmount> /sbin/mount.cifs //%(SERVER)/%(VOLUME) %(MNTPT) -o "user=%(USER),domain=SAMBADOM,uid=%(USER),gid=%(USERGID),cifsacl,file_mode=0700,dir_mode=0700" </cifsmount> <umount>/bin/umount %(MNTPT) </umount> <volume options="username=%(DOMAIN_USER),workgroup=%(DOMAIN_NAME),uid=%(DOMAIN_USER),fmask=700,file_mode=0700,dir_mode=0700" mountpoint="/etudiants/%(USER)" path="...
2017 Nov 10
5
Windows server 2003 domain authentication with Samba version 4.7.0-git.23.4e3f0fb9d15SUSE-oS13.3-x86_64
...r Fodrek > [1] https://wiki.samba.org/index.php/Samba_4.7_Features_added/changed > [2] https://bugzilla.redhat.com/show_bug.cgi?id=1474539 > > > //192.168.1.131/shares /home/fodrek/shares cifs > > credentials=/home/fodrek/ > > cifs.creds,iocharset=utf8,sec=ntlm,cifsacl,user,nosuid,uid=fodrek,gid=use > > rs,vers=1.0 0 0 > > > > > > On tyhe server I am detected as operating system > > Name:openSUSE Tumbleweed > > version: 20171104 > > Service pack: 4.7.0-git.23.4e3f0fb9d15SUSE-oS13.3-x86_64 > > > > Is it poss...
2019 Nov 14
0
Changes in Linux CIFS Kernel Module w.r.t. ACL features
...session expiration, slow >> requests). Improve performance of statfs (add support for compounding of query_fs calls). My question: Which ACL support does it refer to? >> 4.13 Kernel (24 changesets) >> Default dialect changed to SMB3 (from CIFS). SMB3 support added for "cifsacl" mount option (and can now emulate >> retrieving mode from ACL in SMB3). Bug fixes. My question: This enables full support for mapping of CIFS/NTFS ACLs to/from Linux file permission bits as with CIFS/SMBv1? Regards and Best Sebastian Sebastian Kraus Team IT am Institut f?r Chemie...
2015 Jan 23
1
ACL ignored on cifs mounted share
...s what it > expects to find. > > So as I said: > > WINDOWS USER = ACL > > UNIX USER= acl > > Rowland Thanks. So this the default behaviour. Are there any plans to implement the possibility of using ACL's under unix? Because I saw that cifs mount has an option "cifsacl" or is this a totally different feature?