From: L Walsh <cifs@tlinx.org>
To: linux-cifs <linux-cifs@vger.kernel.org>
Subject: multiuser access and group membership(s)
Date: Tue, 13 Apr 2021 12:13:46 -0700 [thread overview]
Message-ID: <6075ED6A.6010603@tlinx.org> (raw)
I tried the multiuser mount using domain-creds.
Surprises:
* Files owned by local accounts appeared to be owned
by 'root:root'.
* Files in well-known-groups, seemed to
resolve ok, but didn't recognize my domain login as
being in one of those groups.
* Files with group ownership of Administrators allowed access
regardless of permission bits (though I am in Administrators group).
-However, files owned (showing in UID) field AdministratorsGroup
showed up as being owned by 'root' from the linux machine and
didn't enable access (though some other rule might).
=== Interesting direction.
I have some disappointment in that the remote Windows machine doesn't
recognize membership in domain groups (or local groups) when
mount options use a domain account (and cifscreds contain a domain
account).
Ex.: (w/Bliss or BLISS being my local NT4-style domain
hosted on the linux box).
local group "lawgroup" on Win machine, contains
BLISS\Domain Admins
Bliss\law
BLISS\lawgroup
law (local account)
yet to 'Bliss/law' on linux, it appears to be
owned by 'root' and doesn't enable access.
Shouldn't the smb server on the win-machine be
able to enable access via domain group membership?
Maybe I just don't have it configured correctly...?
Also noting that unix extensions don't seem to be getting
negotiated. From mount, listed options are:
//Athenae/C/ on /athenae type cifs
(rw,nosuid,nodev,noexec,relatime,vers=2.1,cache=strict,username=law,
domain=BLISS,uid=0,noforceuid,gid=0,noforcegid,addr=192.168.3.12,
file_mode=0755,dir_mode=0755,nocase,soft,resilienthandles,nounix,
setuids,serverino,mapchars,cifsacl,rsize=1048576,wsize=1048576,
bsize=1048576,echo_interval=60,max_credits=60000,actimeo=1,user)
Q: Is it possible to get the Win server to recognize group memberships?
I note that Privileges in the domain aren't acknowledged on
the win-file-system, though the win-user using a samba-mount
will have privs recognized.
Thanks!
next reply other threads:[~2021-04-13 19:47 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-04-13 19:13 L Walsh [this message]
2021-04-14 9:19 ` multiuser access and group membership(s) Aurélien Aptel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6075ED6A.6010603@tlinx.org \
--to=cifs@tlinx.org \
--cc=linux-cifs@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox