search for: vfs_acl_xattr

Displaying 20 results from an estimated 233 matches for "vfs_acl_xattr".

2023 Aug 21
1
...or howto change vfs_acl_xattr options inplace without changing access rights
On 8/18/23 09:55, Sebastian Neustein via samba wrote: > With the default settings of vfs_acl_xattr samba takes posix acls into > account when delivering data - how can I activate > "acl_xattr:ignore system acls = yes" > without loosing the information saved in posix acls? Background: our > future file system won't be able to support acls. Sorry, but this is confusing...
2023 Aug 21
1
...or howto change vfs_acl_xattr options inplace without changing access rights
Hi Ralph > On 8/18/23 09:55, Sebastian Neustein via samba wrote: >> With the default settings of vfs_acl_xattr samba takes posix acls >> into account when delivering data - how can I activate >> "acl_xattr:ignore system acls = yes" >> without loosing the information saved in posix acls? Background: our >> future file system won't be able to support acls. > > Sor...
2009 Mar 04
9
samba 3.3.x vfs_acl_xattr support
>From samba 3.3.0 release notes, it seems like samba 3.3.x is at least experimenting using xattr to store NT ACL, which can eventually provide better NT ACL support. I tried similar features with samba 4.0.0 alpha6, which works very nice. Is there any plan to provide same level of NT ACL support with samba 3.3.x? If there is such plan, any targeted date for that? Thanks, Ying
2010 Sep 22
1
vfs_acl_xattr - moving files/folders
Hello, We've been using samba 3.3.9 with vfs_acl_xattr for some time now, and we do have one issue - when someone moves a file from one place to another (in Windows), it keeps the old ACLs instead of inheriting the new ones. I understand why this is happening (moving as opposed to copying, which actually makes a new file, and thus attains new ACLs...
2023 Aug 18
1
...or howto change vfs_acl_xattr options inplace without changing access rights
...m one old samba server to a new one. Due > to various reasons we had to change some settings. Now I struggle to > get the acls right. > ?Previously the acls were stored via posix and extended attributes, > now they are stored only in extended attributes With the default settings of vfs_acl_xattr samba takes posix acls into account when delivering data - how can I activate "acl_xattr:ignore system acls = yes" without loosing the information saved in posix acls? Background: our future file system won't be able to support acls. Is there a way to migrate all acl information fr...
2014 Aug 20
1
vfs_acl_xattr doesn't work unless all the inherit and map inherit acl parameters are set to yes, but want to set inherit owner = no
I noticed that vfs_acl_xattr doesn't work unless all the inherit and map inherit acl parameters are set to yes. Which is fine but if I turn off inherit owner it completely breaks inheritance and security.NTACL never gets set for the file/directory that's created by the user. I want the uid of the user who's connect...
2023 Aug 21
1
...or howto change vfs_acl_xattr options inplace without changing access rights
On 8/21/23 18:20, Sebastian Neustein wrote: > The storage has come a long way with various changes of the smb.conf. It > is possible that at the time of creation of a file/directory > vfs_acl_xattr was not active. This could mean that the directory does > not have any extended attributes written to it and ACLs are only defined > with POSIX ACLs. In this case I would need a trigger to write the > information stored in POSIX ACLs into the extended attributes. Is there > anything...
2023 Jun 16
1
SaMBa 4.16.4 adds users to ACLs as groups
...from > the mentioned "piling up" of POSIX ACLs, which I discovered 9 days ago. Quite correct, seems I cannot count LOL. > > > >> [quote] >> this "piling up" of ACL information doesn't happen either on a native >> Windows file server or with vfs_acl_xattr >> [/quote] >> Does this mean you do not have 'vfs objects = acl_xattr' in your smb.conf > ? > > Yes, it means that. I don't have vfs_acl_xattr enabled on our infamous > production server, however, I conducted some experiments on a server cloned > from it, wh...
2015 Jan 18
2
Problems with permissions
...Who owns the share directory /home/ldap ? Does 'harry' exist in /etc/passwd ? Does the group 'users' exist in /etc/group and if so, does it have any members ? You do know that Unix acl's are not the same as Windows ACL's and to use windows ACL's you will have to use vfs_acl_xattr Rowland
2016 Mar 12
2
static vs shared modules build
Since all my Samba AD member servers rely on vfs_acl_xattr to take care of Windows permissions, is there any performance advantage to building samba with a static vfs_acl_xattr module? (./configure --with-static-modules=vfs_acl_xattr) Thank you
2023 Jun 16
1
SaMBa 4.16.4 adds users to ACLs as groups
...you for your help with those questions, the migration was successful apart from the mentioned "piling up" of POSIX ACLs, which I discovered 9 days ago. > [quote] > this "piling up" of ACL information doesn't happen either on a native > Windows file server or with vfs_acl_xattr > [/quote] > Does this mean you do not have 'vfs objects = acl_xattr' in your smb.conf ? Yes, it means that. I don't have vfs_acl_xattr enabled on our infamous production server, however, I conducted some experiments on a server cloned from it, where I enabled either vfs_acl_xatt...
2018 Sep 21
1
[SOLVED] Samba 4: 'Access denied' error when accessing user profile during logon
...first en from windows again and the both match again. > > Just dont touch it after you've set it. > > > > Om totaly open for a better setup ;-) and if im wrong here please > > tell me, only with comments, we learn. > > > > > > Try reading 'man vfs_acl_xattr' > > This plainly says that ACLs are stored in the EA 'security.NTACL' > > It also says that when 'acl_xattr:ignore system acls' is set to > 'yes', it will not map to or from the POSIX Layer i.e. the Unix OS. > > It also says the following settin...
2018 Jun 14
1
ACL Anomaly with vfs_acl_xattr on ocfs2 volumes running on ubuntu 18.04
Hello everyone, we are running a CTDB cluster and share folders on ocfs2 volumes via samba using the vfs acl_xattr to store acls in extended attributes. It works fine with Ubuntu 16.04 LTS. I'm currently testing 18.04 and have a weird (but reproducable) ACL behaviour: I grant two users a and user b full access on a folder from a windows client. (Share permissions are fullcontrol for
2010 Oct 08
2
vfs_acl_xattr issue
Hello, I'm using samba 3.4.8~dfsg-2 with "vfs objects = acl_xattr". [share] path = /home/users/xxxx valid users = xxxx read only = No create mask = 0666 directory mask = 0770 vfs objects = acl_xattr Here is my problem, i'm connecting to my share, which have a folder 'f01' with some acl. I created a folder and broke inherit 'f02'.
2023 Jun 20
1
SaMBa 4.16.4 adds users to ACLs as groups
...quot; of POSIX ACLs, which I discovered 9 days ago. > > Quite correct, seems I cannot count LOL. > > > > > > > > >> [quote] > >> this "piling up" of ACL information doesn't happen either on a native > >> Windows file server or with vfs_acl_xattr > >> [/quote] > >> Does this mean you do not have 'vfs objects = acl_xattr' in your > smb.conf > > ? > > > > Yes, it means that. I don't have vfs_acl_xattr enabled on our infamous > > production server, however, I conducted some experiments o...
2023 Jun 16
2
SaMBa 4.16.4 adds users to ACLs as groups
...Hi Tamas, I have been reviewing you numerous posts on this list about this project, are you aware that you have been posting for 6 months ? In your last post there was this: [quote] this "piling up" of ACL information doesn't happen either on a native Windows file server or with vfs_acl_xattr [/quote] Does this mean you do not have 'vfs objects = acl_xattr' in your smb.conf ? You also had this: [quote] this may be the reason why using POSIX ACLs with SaMBa is deprecated [/quote] As far as I am aware, using POSIX ACLs isn't deprecated, is it possible you can tell us where...
2018 May 24
1
Share periodical not accessible
...riubilrthirgnihlndcnhff] -> [lfcnjlndjfgglngietlvkdtkjkrcetvudikfnbgulriubilrthirgnihlndcnhff] -> [LOPRODUCTS\aharms] succeeded [2018/05/23 09:05:04.090820, 2] ../lib/util/modules.c:196(do_smb_load_module) Module 'acl_xattr' loaded [2018/05/23 09:05:04.090848, 2] ../source3/modules/vfs_acl_xattr.c:193(connect_acl_xattr) connect_acl_xattr: setting 'inherit acls = true' 'dos filemode = true' and 'force unknown acl user = true' for service Transfer [2018/05/23 09:05:04.091137, 2] ../source3/smbd/service.c:774(make_connection_snum) macbook-ah (ipv4:10.1.0.3:59252) co...
2024 Jun 06
1
How to give AD users group permissions on a Samba share
...ks to the smb.conf > (removing guest ok|only, ...) and it continued to work. Now I have > needs that apparently extend beyond what the "old-style" can support. Basically, the old NT4-style domains relied on setting permissions in the share part of the smb.conf file, but, by using vfs_acl_xattr, you can set finer control from Windows and these acls are stored Extended Attributes (EAs). > > So. I've followed the procedures in your referenced link. and am at > the section titled: "Setting Share Permissions and ACLs". I am > setting this up on a test system. Befor...
2024 Jun 07
1
How to give AD users group permissions on a Samba share
...rpenny at samba.org> wrote; > > On Thu, 06 Jun 2024 13:37:34 -0400 > Mark Foley via samba <samba at lists.samba.org> wrote: > > > [snip] > > Basically, the old NT4-style domains relied on setting permissions in > the share part of the smb.conf file, but, by using vfs_acl_xattr, you > can set finer control from Windows and these acls are stored Extended > Attributes (EAs). > > > > > So. I've followed the procedures in your referenced link. and am at > > the section titled: "Setting Share Permissions and ACLs". I am > > setti...
2016 Mar 12
0
static vs shared modules build
Am 12.03.2016 um 19:48 schrieb Miguel Medalha: > Since all my Samba AD member servers rely on vfs_acl_xattr to take care > of Windows permissions, is there any performance advantage to building > samba with a static vfs_acl_xattr module? > > (./configure --with-static-modules=vfs_acl_xattr) no, it only has a theoretical impact on the number of open filehandles, theroretical means in that co...