Setting samba file security in a ADS setup.

From: Andrew Watkins (andrew@dcs.bbk.ac.uk)
Date: Tue Nov 01 2005 - 08:18:51 EST


Hi,

We have been using Samba for ages to share UNIX filestore to Windows machines
with out any problems (domain control is a Windows 2003 box ADS). Our setup
is that users have two network drives on there PC's (Samba share and a Windows
share) and they have duplicate accounts on both Windows and Solaris.

We have this setup since samba shares do not allow users to change the security
of files (.i.e. a user may want to allow a another user / group to access there
files). Of course there is no such problem with the windows filesystem.

I have been looking at the samba pages and I am not sure if it can be done,
since it does not directly mention this. What it does mention is that I
need to setup samba with LDAP to map Solaris(NIS) UID with Windows(ADS) SID,
which looks like a major project and may mean dropping NIS!

If someone has gone through this problem please let me know of how to solve it.

The reason for this e-mail now is that our manager was about to purchase more
Windows filestore, but I suggested expanding our UNIX this problem, but that is
not going to happen if I don't solve this problem.

A "HOW TO" would be great, since it would save a lot of time

Thanks

Andrew Watkins
*****************************************************************************
Unix Administrator tel: 020-7631 6720
Computer Science Department fax: 020-7631 6727
Birkbeck College (University of London)
Malet Street
London e-mail: andrew@dcs.bbk.ac.uk
WC1E 7HX http://www.dcs.bbk.ac.uk/~andrew
*****************************************************************************
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers



This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 23:34:10 EDT