[OmniOS-discuss] SMB issues after r151014 -> r151018

Olaf Marzocchi lists at marzocchi.net
Fri Apr 22 10:20:49 UTC 2016


Thanks,
I didn't know that. I thought that it was better not to leave anything undefined, so after a positive match for the intended user, I added a deny for everyone else, thinking that the order of the ACLs also gave priority to the allow statements.

After your explanation, I will just remove the deny ACL, it's not needed in my case.

Olaf



Il 22 aprile 2016 03:53:18 CEST, Gordon Ross <gordon.w.ross at gmail.com> ha scritto:
>I'm not sure how anyone ever gets access when your ACL has this ACE:
>        everyone@:rwxpdDaARWcCos:fd-----:deny
>
>Every logon has the group "everyone" as a member, therefore that ACE
>will match every logon.  The ace also lists every possible permission,
>so nothing should get through, no matter what allow ACEs might also
>exist.



More information about the OmniOS-discuss mailing list