Hi All,
I've spent some time on it and only got tired, probably I miss some relevant information here...
I'm using FreeNAS-9.2.1.7-RELEASE-x86 and my CIFS shares use Unix permissions. I have to use extended acl to have necessary granularity. Here comes the problem:
[root@freenas] /mnt/storage# ls -ld Ewidencja/
drwx------+ 5 Maciek Ewidencja 512 Sep 8 23:14 Ewidencja//
[root@freenas] /mnt/storage# getfacl Ewidencja/
# file: Ewidencja/
# owner: Maciek
# group: Ewidencja
user:Iza:rwxpDdaARWcCos:------:allow
owner@:rwxp--aARWcCos:------:allow
group@:------a-R-c--s:------:allow
everyone@:------a-R-c--s:------:allow
So when user Iza is logged through ssh she has all above (extended) permissions to the directory and can create files directories etc.
but using smbclient Iza can't even list the content of directory:
smb: \> ls
NT_STATUS_ACCESS_DENIED listing \*
it looks like using samba only the standard unix privileges are considered and extended acl not - does it work "as designed" or I missed something? I double checked different options and so on but haven't found anything.
Thx,
Piotr
I've spent some time on it and only got tired, probably I miss some relevant information here...
I'm using FreeNAS-9.2.1.7-RELEASE-x86 and my CIFS shares use Unix permissions. I have to use extended acl to have necessary granularity. Here comes the problem:
[root@freenas] /mnt/storage# ls -ld Ewidencja/
drwx------+ 5 Maciek Ewidencja 512 Sep 8 23:14 Ewidencja//
[root@freenas] /mnt/storage# getfacl Ewidencja/
# file: Ewidencja/
# owner: Maciek
# group: Ewidencja
user:Iza:rwxpDdaARWcCos:------:allow
owner@:rwxp--aARWcCos:------:allow
group@:------a-R-c--s:------:allow
everyone@:------a-R-c--s:------:allow
So when user Iza is logged through ssh she has all above (extended) permissions to the directory and can create files directories etc.
but using smbclient Iza can't even list the content of directory:
smb: \> ls
NT_STATUS_ACCESS_DENIED listing \*
it looks like using samba only the standard unix privileges are considered and extended acl not - does it work "as designed" or I missed something? I double checked different options and so on but haven't found anything.
Thx,
Piotr