- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Samba and WINDOWS NTFS permissions
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-12-2008 10:36 AM
11-12-2008 10:36 AM
I am trying to manage samba shared directories using Windows NTFS permissions. What I mean is that I want to be able to manage user’s permissions on Samba shared directories using Windows NTFS security. I have been looking all around the web and found some stuff but I am stuck. I have created a new filesystem for testing and try to do the following in /etc/fstab:
/dev/vg00/lvol15 /samba_drives vxfs rw,suid,largefiles,delaylog,datainlog,acl 02
I read that I need to enable acl on the filesystem and then mount it but I get an error saying that acl parameter is not recognized.
I know I will have to make sure in Samba that the shared directory has NT ACL SUPPORT set to YES.
Any help would be appreciated.
Stephane
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-12-2008 02:13 PM
11-12-2008 02:13 PM
Re: Samba and WINDOWS NTFS permissions
Eric Roseme
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-13-2008 08:00 AM
11-13-2008 08:00 AM
Re: Samba and WINDOWS NTFS permissions
I can't find JFS installed...see :
/opt/samba/bin # swlist | grep JFS
Return nothing.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-13-2008 01:08 PM
11-13-2008 01:08 PM
Re: Samba and WINDOWS NTFS permissions
Take that "acl" off the mount command, mount the FS, then share it with CIFS.
One thing that is overlooked is that CIFS uses the /var/opt/samba/private/smbpasswd file as the source for user-data for ACL support. I know it's weird, but that's the way it is. So look at your smbpasswd file and see if your user records are in it. If not, then run syncsmbpasswd.
That's assuming that you can right click on your share files and directories and you know how to navigate for ACL management, but you do not see users/groups to add or assign rights to.
Eric
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-13-2008 01:19 PM
11-13-2008 01:19 PM
Re: Samba and WINDOWS NTFS permissions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-14-2008 02:08 PM
11-14-2008 02:08 PM
Re: Samba and WINDOWS NTFS permissions
I will not be back here until at least Monday, tho.
Later,
Eric
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-18-2008 07:48 AM
11-18-2008 07:48 AM
Re: Samba and WINDOWS NTFS permissions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-18-2008 09:08 AM
11-18-2008 09:08 AM
SolutionI suggest that you use username.map to troubleshoot, then look into the other options for a long-term solution.
Eric
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-18-2008 11:51 AM
11-18-2008 11:51 AM
Re: Samba and WINDOWS NTFS permissions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-19-2008 09:16 AM
11-19-2008 09:16 AM
Re: Samba and WINDOWS NTFS permissions
Eric
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-19-2008 10:38 AM
11-19-2008 10:38 AM
Re: Samba and WINDOWS NTFS permissions
user1=user1
That's my user name for UNIX and Windows.
Here is what I found under /var/opt/samba in log.q202642 (name of my computer)
/var/opt/samba # more log.q202642
[2008/11/19 13:30:08, 1] smbd/service.c:make_connection_snum(642)
q202642 (10.1.3.137) connect to service Informatique initially as user insg (u
id=0, gid=1000) (pid 172)
[2008/11/19 13:30:10, 1] smbd/service.c:close_cnum(829)
q202642 (10.1.3.137) closed connection to service Informatique
[2008/11/19 13:30:13, 1] smbd/service.c:make_connection_snum(642)
q202642 (10.1.3.137) connect to service Informatique initially as user insg (u
id=0, gid=1000) (pid 172)
[2008/11/19 13:30:18, 0] smbd/posix_acls.c:create_canon_ace_lists(1388)
create_canon_ace_lists: unable to map SID S-1-5-21-384314138-255804918-1540833
222-4216 to uid or gid.
And here is what's in /var/opt/samba/log.winbindd
[2008/11/19 13:25:39, 1] nsswitch/winbindd.c:main(864)
winbindd version 3.0.14a based HP CIFS Server A.02.02 started.
Copyright The Samba Team 2000-2004
[2008/11/19 13:25:39, 0] nsswitch/winbindd_util.c:winbindd_param_init(555)
winbindd: idmap uid range missing or invalid
[2008/11/19 13:25:39, 0] nsswitch/winbindd_util.c:winbindd_param_init(556)
winbindd: cannot continue, exiting.
[2008/11/19 13:25:39, 1] nsswitch/winbindd.c:main(897)
Could not init idmap -- netlogon proxy only
[2008/11/19 13:26:00, 1] nsswitch/winbindd_sid.c:winbindd_uid_to_sid(404)
Could not convert uid 0 to rid
[2008/11/19 13:30:14, 1] nsswitch/winbindd_sid.c:winbindd_uid_to_sid(404)
Could not convert uid 0 to rid
When I tried to modify permission from Windows screen, I do add user1 and change permissions but when pressing Apply, user1 disappears.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-20-2008 01:43 PM
11-20-2008 01:43 PM
Re: Samba and WINDOWS NTFS permissions
idmap uid = 10000-20000
idmap gid = 10000-20000
template homedir = /home/%U
template shell = /usr/bin/sh
winbind separator = +
winbind enum users = yes
winbind enum groups = yes
winbind use default domain = yes
You'll need to add winbind to nsswitch.conf. Start the daemon, and do a "wbinfo -u" and a "wbinfo -g" to make sure that the IDs get resolved. Also, you will still need to run syncsmbpasswd, because CIFS looks for the ACL names there.
or, make sure winding is not running, make sure that your user names are in smbpasswd, and use the username.map file.
Obviously, this gets a little complex. You may need to call the RC.
Eric
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-21-2008 10:21 AM
11-21-2008 10:21 AM
Re: Samba and WINDOWS NTFS permissions
CIFS A.03.02.04
krb5client D.1.6.2
ldapuxclient B.04.17
HP-UX 11.23
JFS 4.1 layout 5
Eric
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-21-2008 10:30 AM
11-21-2008 10:30 AM