Steiner-SE
Dabbler
- Joined
- Jul 13, 2020
- Messages
- 37
Ok, to figure out permissions and ACLs I've made an experimental share that I keep changing the ACL entries to (restarting service after each change)
On the Windows side I disconnect the share and remaps it for each change to see differences, I try both mapping directly (windows credentials) and using different credentials (using the truenas account name/pass, but really the same as the windows credential).
I noticed that using owner@ and group@ adds additional permission entries on the windows side so I'm now setting the specific user and group and only get those two entries on the windows side.
Now here what has me confused. On the windows side no matter how I map the share (windows authentication or truenas credentials) and despite having set up permissions identically for user and group in TrueNAS what I see are two completely different things.
For the group entry (which always takes a bit longer to populate) when I select the security tab and click on the group all check marks except "Full Control" are set, as expected.
I'd expect the same to be true for the user entry (which is always populated, no delay), but when I click on that entry no check marks expect "special permissions" are set. With identical ACls set in the NAs shouldn't they appear the same here? This is the same regardless of how I map the share as mentioned.
I have taken the NAS of the domain but that lab machine is still in the domain, might this account for the discrepancy (despite using explicit TrueNAS credentials)?
I hope I made this understandable and clear enough?
On the Windows side I disconnect the share and remaps it for each change to see differences, I try both mapping directly (windows credentials) and using different credentials (using the truenas account name/pass, but really the same as the windows credential).
I noticed that using owner@ and group@ adds additional permission entries on the windows side so I'm now setting the specific user and group and only get those two entries on the windows side.
Now here what has me confused. On the windows side no matter how I map the share (windows authentication or truenas credentials) and despite having set up permissions identically for user and group in TrueNAS what I see are two completely different things.
For the group entry (which always takes a bit longer to populate) when I select the security tab and click on the group all check marks except "Full Control" are set, as expected.
I'd expect the same to be true for the user entry (which is always populated, no delay), but when I click on that entry no check marks expect "special permissions" are set. With identical ACls set in the NAs shouldn't they appear the same here? This is the same regardless of how I map the share as mentioned.
I have taken the NAS of the domain but that lab machine is still in the domain, might this account for the discrepancy (despite using explicit TrueNAS credentials)?
I hope I made this understandable and clear enough?