1847279 Members
2929 Online
110263 Solutions
New Discussion

Re: Samba Security

 
Cifs 9000
Advisor

Samba Security

I joined my samba server with ads windows2000.

i have one share directory test
Inside test directory i have around 10 directory. i want to give access to specific windows global group to particular directory
example: Global group name : accounts
group can access only share : test/acct10
and other has no access on that directory.
I don't want to create any user and local unix and samba group.
Please let me know if its possible . how can i do it from windows 2000 site.
should i need dedicate windows workstation for samba share because generally we are adding/removing user from groups.


4 REPLIES 4
Geoff Wild
Honored Contributor

Re: Samba Security

Yes you can do it - but you can't adminster from Windows (well I guess you can - you could use SWAT via a web browser).

Try something like:

[test]
comment = Network Drive
path = /some/path/test
valid users = @accounts, @"DOMAIN+accounts"
read only = no
browseable = yes


I'm assuming your winbind separator = +



Rgds...Geoff
Proverbs 3:5,6 Trust in the Lord with all your heart and lean not on your own understanding; in all your ways acknowledge him, and he will make all your paths straight.
Cifs 9000
Advisor

Re: Samba Security

It means i cannot give permission from windows site. example.

1. login to windows domain as admin.
2. give share permission to specific group
Cifs 9000
Advisor

Re: Samba Security

i couldn't see the option of valid user in swat.

suppose domain : xyz

@"xyz+accounts"

accounts : windows group
Cifs 9000
Advisor

Re: Samba Security

thanks