similar to: acl_xattr and root permissions

Displaying 20 results from an estimated 10000 matches similar to: "acl_xattr and root permissions"

2018 Dec 07
0
acl_xattr and root permissions
Hai, Tip, think in groups not users when you setup/manage you servers, it will help. Now, root = Administrator user != Administrator but when you add a user as member of domain admins... because root = "Domain Admins" Read : https://wiki.samba.org/index.php/Setting_up_a_Share_Using_Windows_ACLs Dont forget also the "Creator owner" and "Creator Group"
2018 Dec 09
2
Robocopy, archive bit and ACLs
Hello, I'm attempting to set up a daily Robocopy task on a Windows Server 2016 to duplicate a large directory tree -- including data, timestamps and ACLs -- to a Samba 4.5.12 server. This is my Robocopy command: Robocopy.exe C:\source \\foo\bar /XA:SH /XJ /MIR /NODCOPY /COPY:DTSO /A+:A /ZB I noticed that for a significant number of files, Robocopy will systematically identify them as
2017 Feb 22
2
Windows file directory creation permission confusion
Samba 4 Simple Samba file share, Domain Controller Users - windows 7 I am having problems getting folder and file permissions to working properly from the Windows clients. No setting I change in smb.conf have any effect on files and folders created from windows clients. (I see this kind of question a lot other places so you must be tired of it.) Smb.conf [GLOBAL] force create mode = 0770
2023 Nov 28
1
Setting up Profiles share... 777?!
On Tue, 28 Nov 2023 16:00:22 +0100 Marco Gaiarin via samba <samba at lists.samba.org> wrote: > > In a fresh samba AD domain i'm setting up the 'Profiles' share for > roaming profiles, following the wiki: > > https://wiki.samba.org/index.php/Roaming_Windows_User_Profiles > https://wiki.samba.org/index.php/Setting_up_a_Share_Using_Windows_ACLs > >
2024 Jan 30
2
Behavior of acl_xattr:ignore system acls = yes on a share
On 30.01.2024 16:51, Ralph Boehme via samba wrote: > On 1/30/24 16:27, Rowland Penny via samba wrote: >> On Tue, 30 Jan 2024 16:13:41 +0100 >> Peter Milesson via samba <samba at lists.samba.org> wrote: >> >>> Hi folks, >>> >>> It seems that the setting acl_xattr:ignore system acls = yes reduces >>> Windows compatibility when defined
2024 Jan 31
1
Behavior of acl_xattr:ignore system acls = yes on a share
Does you filesystem support extended attributes? What does "|getfattr -n security.NTACL |filename" return?|| On 30.01.2024 16:13, Peter Milesson wrote: > Hi folks, > > It seems that the setting acl_xattr:ignore system acls = yes reduces > Windows compatibility when defined for a share. In all attempts I have > used Windows tools (except editing smb.conf) > > Assume
2017 Jun 13
5
Retaining Permissions on a share
Hi Rowland, Thank you for the reply and info. On Tue, Jun 13, 2017 at 11:19 AM, Rowland Penny <rpenny at samba.org> wrote: > On Tue, 13 Jun 2017 09:15:40 +0200 > Neil via samba <samba at lists.samba.org> wrote: > > > OK, this a DC and therefore you will have to do things differently from > a Unix domain member. > > You might as well remove these lines from
2017 Nov 30
4
Troubles on Roaming Profiles...
Mandi! Rowland Penny via samba In chel di` si favelave... > Is this on a DC ? No, is a DM. > If it isn't, Try setting it up exactly like it is shown on the > wikipage, note that you only need the 'vfs objects' line if it isn't > set in [global] Wikipage say only: Create a new share. For details, see Setting up a Share Using Windows ACLs. and
2020 Feb 05
4
Samba, ACLs and 'primary group'...
My previous email on this topic get no answer, i try to explain me better. The problem. Simply i was (ab)used, in my previous samba NT-mode domains, to have file created with the group-owner as the UNIX primary group; now, in AD, files get created group-owned by Windows primary group, eg 'Domain Users'. This simply 'breaks' most of my ACLs setup. I've read:
2024 Jan 30
2
Behavior of acl_xattr:ignore system acls = yes on a share
Hi folks, It seems that the setting acl_xattr:ignore system acls = yes reduces Windows compatibility when defined for a share. In all attempts I have used Windows tools (except editing smb.conf) Assume there is a share, where the files and folders in the share root should at least be readable by anybody having access to the share. For the sake of simplicity the following permissions apply on
2020 Nov 11
0
acl_xattr - AD Computer Management - Failed to enumerate objects in container
I am following this guide https://wiki.samba.org/index.php/Setting_up_a_Share_Using_Windows_ACLs But hitting issues with setting permissions on the share in Computer Management in the windows AD DC UI. Every time I try I get the error dialog with +----------------------------------------------------------------+ | An error occurred while applying security information to | |
2023 Mar 22
0
Purpose and functionality of "acl_xattr:ignore system acls"
Hello, I am currently struggling to understand the samba share configuration "acl_xattr:ignore system acls". I followed the wiki page https://wiki.samba.org/index.php/Setting_up_a_Share_Using_Windows_ACLs to configure shares for windows clients. My observations so far: I start with "acl_xattr:ignore system acls=no" and create a samba share. Afterwards, I use a windows client
2017 Mar 30
3
Failed to enumerate objects in the container. Access is denied.
> Rowland Penny <rpenny at samba.org> hat am 30. März 2017 um 16:46 geschrieben: > If you look here: > > drwxrwx---+ 2 RUBENS\gf root 4096 Mär 30 14:09 gf > > There is a '+' sign after the permissions, this means that there are > ACLs set on the directory, try running 'getfacl /fs/gf' Ok, first /fs/mrtx, then /fs/gf: root at fs:~# getfacl /fs/mrtx
2017 Jul 03
2
Can't create/update Group Policy in Samba 4.6.5
Hai, In reponse to the why i recommend that. Since this is a "windows" only share, i recomment to set it up for that usage, with results in better matching for windows rights. Resulting in better working policies. The current POSIX rights did not match to my needs and resulted in inconsistant policies. This is why i use these for profiles and sysvol. And this is my setup order:
2017 Apr 12
4
Dir ACL through windows and chmod
Samba-4.3.5, Debian smb.conf === [global] workgroup = WG security = ADS realm = WG.LOCAL dedicated keytab file = /etc/krb5.keytab kerberos method = secrets and keytab server string = Samba 4 Client %h idmap config * : backend = tdb idmap config * : range = 2000-10000 idmap config * : backend = rid idmap config * : range = 300000-400000 #
2018 Nov 28
2
Fw: AD usres are not show in Domain Controller when apply setfacl command
Dear Team I show below my problem when try to apply setfacl to share directory in domain controller My Problem is: I have one Samba AD [4.1] it work fine. I create common share folder in domain controller when try to apply ACL permission it show the following message [root at sambadc ~]# setfacl -m "u:RISHI\Administrator:rwx" /ADD_Drive/Samplesetfacl: Option -m: Invalid argument near
2017 Nov 30
2
Troubles on Roaming Profiles...
I've created a folder for roaming profiles: [profiles] comment = Network Profiles Share path = /srv/samba/profiles browseable = No store dos attributes = Yes csc policy = disable map acl inherit = Yes read only = No vfs objects = acl_xattr Share permission and folder permission seems right, exactly as in: https://wiki.samba.org/index.php/Roaming_Windows_User_Profiles I've
2019 Jan 08
5
idmap problems
<snip> Hi Rowland - I've spent the past few days going over the wiki and mailing lists. I think I've got the hang of idmaps. May I clarify a couple of things: ~ I have two DC's and one large fileserver (member). I'm using the 'ad' backend. ~ The only only windows group that needs a gidNumber attribute is Domain Users to map this across to the member server. ~ Other
2017 Jul 02
4
Can't create/update Group Policy in Samba 4.6.5
Hi, I'm using Samba 4.6.5 and I have installed as follows: wget -c https://download.samba.org/pub/samba/stable/samba-4.6.5.tar.gz tar -xzvf samba-4.6.5.tar.gz cd samba-4.6.5 ./configure --enable-debug --enable-selftest make make install It seems that is working properly, however I can't create or update GPO with Windows Group Policy Management tool. When I try, "Denied
2020 Sep 08
4
ACLs, groups and suid-bit?
On Tue, 8 Sep 2020, Rowland penny via samba wrote: > On 08/09/2020 13:55, Harald Hannelius wrote: >> >> On Tue, 8 Sep 2020, Rowland penny via samba wrote: >>> On 08/09/2020 13:27, Harald Hannelius via samba wrote: >>>> >>>> Hello, >>>> >>>> I have users in Samba AD with uid- and gidnumbers. I also have group