Solved

SAMBA 3 + ACLs: Different access rights in Linux and Windows

Posted on 2011-03-17
2
637 Views
Last Modified: 2012-08-13
Dear Experts,

just an understanding question. I have a SAMBA share with the following ACL settings:

getfacl /share

# file: share
# owner: root
# group: root
user::rwx
group::rwx
group:mygroup1:rwx
group:mygroup2:r-x
mask::rwx
other::r-x

Open in new window


I'm not able to create/edit files on the Linux (Samba) server as a member of mygroup2:

touch test.file

touch: cannot touch `test.file': Permission denied

Open in new window


Logged on a Windows 2008 Server I see the same access rights like on the Linux server, but I can create files. Is it a correct behavior for the following configuration? My aim was to give the mygroup2 just a read access

[share]
        comment = share
        path = /share
        valid users = @mygroup1, @mygroup2
        force group = mygroupe1
        force create mode = 0770
        force directory mode = 0770
        read only = No
        inherit acls = Yes

Open in new window


Thank you in advance!
0
Comment
Question by:atyur
2 Comments
 
LVL 2

Accepted Solution

by:
silvanx earned 250 total points
ID: 35157381
How about changing
force group = mygroupe1

Open in new window

to
force group = +mygroup2

Open in new window


This should force access level of mygroup2 for its members and default access to everybody else.
0
 

Author Closing Comment

by:atyur
ID: 35164235
Yes, you're right. Thank you!
0

Featured Post

Master Your Team's Linux and Cloud Stack!

The average business loses $13.5M per year to ineffective training (per 1,000 employees). Keep ahead of the competition and combine in-person quality with online cost and flexibility by training with Linux Academy.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
I'm a big fan of Windows' offline folder caching and have used it on my laptops for over a decade.  One thing I don't like about it, however, is how difficult Microsoft has made it for the cache to be moved out of the Windows folder.  Here's how to …
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question