CIFS share AD permissions

Status
Not open for further replies.
Joined
Feb 13, 2014
Messages
3
Hello all,

I think I've searched suitably and am coming up empty handed. I have set up a freeNAS box that I am trying to replace an aging Windows box with. The purpose of the box is to be connected with several file shares to receive scanned documents across the network from several MFDs.

I am running FreeNAS-9.2.0-RELEASE-x64 (ab098f4). I have the freenas box talking to AD and can see all my users and groups. I have my volume set to windows ACL and myself and one of my member AD groups as the owner of the volume.

My problem is this: I have seen in other tutorials that once the shares are created you can manage permissions through a windows computer in the security tab on the share.

I have created several test shares but when I change the permissions from windows for any one share it changes the permissions on all shares. I need to have my shares have different permissions.

I hope this is somewhat clear.

Thanks,
Brian
 
Joined
Feb 13, 2014
Messages
3
Nope. I also tried creating one share with subfolders and making the subfolders more restrictive with regards to permissions. All permissions set on any one object through the windows GUI appear to propagate to all other objects.

I haven't spent too much more time trying to get it to work. Probably just set up another windows box to save time.
 

bigphil

Patron
Joined
Jan 30, 2014
Messages
486
I think the problem is essentially the same as this thread. See my comment (post #2 in the thread) and it should help you out. The issue is the dataset permissions are getting pushed down the line to the CIFS shares if you don't overwrite the "share permissions" (not to be confused with the NTFS permissions). Also...you'll need to be on at least FreeNAS 9.2.1 release...or newer, for the share permissions to persist across reboots of the FreeNAS box.
 
Joined
Feb 13, 2014
Messages
3
Thanks for the reply and tip. I updated to 9.2.1.3 and ended no longer being able to see any of my AD groups without having changed anything else. My AD users are all still present. I think I'm going to call it quits so I can keep some of my hair.
 

bigphil

Patron
Joined
Jan 30, 2014
Messages
486
Did you try to refresh the directory cache? settings/advanced I think. there is a button at the bottom. also...check out #6 post from John here. Don't give up so easily ;)
 
Status
Not open for further replies.
Top