Author Topic: SOLVED: Samba ACL problem  (Read 5566 times)

xsynek@volny.cz

  • Zen Apprentice
  • *
  • Posts: 6
  • Karma: +0/-0
    • View Profile
SOLVED: Samba ACL problem
« on: November 20, 2011, 11:45:32 am »
Hi,
I have problem with ACL permission settings. User that has no ACL rights to subdirectory can read and write :-(
username is:  zak
group member:  zaci

smbd.conf  - share

[data]
 comment = data
 path = /home/samba/shares/data
 browseable = yes
 read only = no
 valid users = @"vedeni", @"zaci", @"ucitele", @"spravci"
 read list =
 write list = @"vedeni", @"zaci", @"ucitele"
 admin users = @"spravci"
 force create mode = 0660
 force directory mode = 0660
 vfs objects = full_audit recycle
 recycle: versions = Yes
 recycle: repository = RecycleBin
 recycle: keeptree = Yes
 recycle: excludedir = /tmp|/var/tmp
 recycle: directory_mode = 0700


ACL permission dir data:
# file: .
# owner: ebox
# group: __USERS__
user::rw-
group::rwx
group:vedeni:rwx
group:ucitele:rwx
group:zaci:rwx
mask::rwx
other::---
default:user::rw-
default:group::rwx
default:group:vedeni:rwx
default:group:ucitele:rwx
default:group:zaci:rwx
default:mask::rwx
default:other::---

ACL permission subdir vedeni:
# file: Vedeni/
# owner: ebox
# group: __USERS__
user::rw-
group::rwx
group:vedeni:rwx
mask::rwx
other::---
default:user::rw-
default:group::rwx
default:group:vedeni:rwx
default:mask::rwx
default:other::---

But user "zak" has RW access :-( Where is the problem? Please help.
Thank for all advise.
Petr
« Last Edit: December 02, 2011, 02:40:48 pm by xsynek@volny.cz »

Mittelerde

  • Zen Warrior
  • ***
  • Posts: 153
  • Karma: +8/-0
    • View Profile

xsynek@volny.cz

  • Zen Apprentice
  • *
  • Posts: 6
  • Karma: +0/-0
    • View Profile
Re: Samba ACL problem
« Reply #2 on: November 20, 2011, 02:08:55 pm »
Yes, here is row from sftab.

/dev/mapper/raid-home /home           ext4    defaults,usrquota,grpquota,acl        0       2

xsynek@volny.cz

  • Zen Apprentice
  • *
  • Posts: 6
  • Karma: +0/-0
    • View Profile
Re: Samba ACL problem
« Reply #3 on: November 20, 2011, 02:29:06 pm »
I tried revoke right from Win Security settings. Here is result by getfacl:
 getfacl Vedeni/
# file: Vedeni/
# owner: ebox
# group: __USERS__
user::rwx
group::rwx
group:vedeni:rwx
group:zaci:---
mask::rwx
other::---
default:user::rwx
default:group::rwx
default:group:vedeni:rwx
default:group:zaci:---
default:mask::rwx
default:other::---

User zak (member zaci, no other group) has still RW access to dir Vedeni. What is wrong? :(

Mittelerde

  • Zen Warrior
  • ***
  • Posts: 153
  • Karma: +8/-0
    • View Profile
Re: Samba ACL problem
« Reply #4 on: November 21, 2011, 09:56:53 am »
   do you have the same error if you temporarily give the user(zak) or group(zaci) admin rights ?

xsynek@volny.cz

  • Zen Apprentice
  • *
  • Posts: 6
  • Karma: +0/-0
    • View Profile
Re: Samba ACL problem
« Reply #5 on: December 02, 2011, 02:39:16 pm »
I solved my problem. Unix right is now  ebox:ebox and then ACL rights are working correctly.