Bug 999484 - Not able to set deny acls on samba shares
Not able to set deny acls on samba shares
Status: CLOSED EOL
Product: Red Hat Gluster Storage
Classification: Red Hat
Component: samba (Show other bugs)
2.1
Unspecified Unspecified
high Severity medium
: ---
: ---
Assigned To: Ira Cooper
Lalatendu Mohanty
ntacl
:
Depends On:
Blocks: 1110018
  Show dependency treegraph
 
Reported: 2013-08-21 07:52 EDT by Lalatendu Mohanty
Modified: 2015-12-03 12:13 EST (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 1110018 (view as bug list)
Environment:
Last Closed: 2015-12-03 12:13:26 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Lalatendu Mohanty 2013-08-21 07:52:21 EDT
Description of problem:

We are not able to set deny acls on samba shares. samba shares include rhs volumes, xfs partitions. This might be because deny acls are not supported with samba. However we are not sure about this. So this bug would be used to track this issue. 

If we confirm samba does not support deny acls, we would convert this bug as documentation bug to include the information in rhs documentation.



Version-Release number of selected component (if applicable):
samba-3.6.9-159.1

How reproducible:
always
Comment 2 Christopher R. Hertel 2013-08-21 21:34:44 EDT
The vfs_glusterfs module does not support storage and retrieval of Windows ACLs. Instead, it converts the Windows ACLs into POSIX ACLs (as best as it can) and stores the POSIX ACLs in the file system. This ensures that other applications and access methods are all obeying the same access rules. When Windows asks to read a Security Descriptor (SD), the POSIX ACLs are translated back into Windows format (as best as we can) and the SD is constructed from the result.

POSIX doesn't have a concept of Deny ACLs, so there is no way to retrieve a Deny ACL using this mechanism.
Comment 3 Raghavendra Talur 2013-08-27 01:30:46 EDT
You can use acl_xattr object on top of glusterfs to support NT_ACLs.
But we have not tested its integration throughly yet.
Comment 4 Christopher R. Hertel 2013-08-27 14:17:17 EDT
Agreed.

The solution is to test the addition of the vfs_acl_xattr module above the vfs_glusterfs module in the Samba VFS stack. This stacking should work, but we have not tested it fully to verify it for production use.
Comment 5 Lalatendu Mohanty 2013-09-11 08:44:13 EDT
We should also take this bug as high severity because it is important from Windows security point of view. 

In Windows if a set of permissions given to a to a particular group and we can set deny acl for a for a particular user from the group. While calculating the final permission for the user, deny acl take higher precedence and the deny acl will be applicable for the user.
Comment 6 Christopher R. Hertel 2013-10-02 15:39:49 EDT
This simply requires QE testing with the vfs_acl_xattr module.
Comment 7 Vivek Agarwal 2015-12-03 12:13:26 EST
Thank you for submitting this issue for consideration in Red Hat Gluster Storage. The release for which you requested us to review, is now End of Life. Please See https://access.redhat.com/support/policy/updates/rhs/

If you can reproduce this bug against a currently maintained version of Red Hat Gluster Storage, please feel free to file a new report against the current release.

Note You need to log in before you can comment on or make changes to this bug.