Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 649
  • Last Modified:

SAMBA 3 + ACLs: Different access rights in Linux and Windows

Dear Experts,

just an understanding question. I have a SAMBA share with the following ACL settings:

getfacl /share

# file: share
# owner: root
# group: root
user::rwx
group::rwx
group:mygroup1:rwx
group:mygroup2:r-x
mask::rwx
other::r-x

Open in new window


I'm not able to create/edit files on the Linux (Samba) server as a member of mygroup2:

touch test.file

touch: cannot touch `test.file': Permission denied

Open in new window


Logged on a Windows 2008 Server I see the same access rights like on the Linux server, but I can create files. Is it a correct behavior for the following configuration? My aim was to give the mygroup2 just a read access

[share]
        comment = share
        path = /share
        valid users = @mygroup1, @mygroup2
        force group = mygroupe1
        force create mode = 0770
        force directory mode = 0770
        read only = No
        inherit acls = Yes

Open in new window


Thank you in advance!
0
atyur
Asked:
atyur
1 Solution
 
silvanxCommented:
How about changing
force group = mygroupe1

Open in new window

to
force group = +mygroup2

Open in new window


This should force access level of mygroup2 for its members and default access to everybody else.
0
 
atyurAuthor Commented:
Yes, you're right. Thank you!
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now