[prev in list] [next in list] [prev in thread] [next in thread] 

List:       samba-technical
Subject:    Re: Samba4 Inheritance of directory ACLs
From:       Lukasz Zalewski <lukas () eecs ! qmul ! ac ! uk>
Date:       2012-08-31 9:02:42
Message-ID: 50407DB2.6020106 () eecs ! qmul ! ac ! uk
[Download RAW message or body]

On 30/08/12 21:29, Marc Muehlfeld wrote:
> Hello,
>
> I played with delegation today, too. I wanted to allow a non-admin user
> to edit a group policy on an OU. But when I switched to this user, I
> could open the group policy, but when I made changes and clicked 'OK', I
> got 'access denied'. I even gave the user 'full access'.
>
> I did this with 4.0.0beta8-GIT-24356f3.

Hi Marc,
I have had limited success with delegation of privileges. Please see
https://bugzilla.samba.org/show_bug.cgi?id=8909

There are also other ACL releated bugs (listed in one of Metze's emails 
sent to the list few weeks ago).

However you should be able to delegate full access - do note that if you 
already have existing objects in that container, you will have to 
propagate the privileges youself.
Newly created object will inherit those delegated privileges correctly 
though.

Regards

L
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic