Setting Share Permissions & ACL's remotely to ubuntu 16.04 Samba file server via Windows Server 2012 r2


Recommended Posts

Hi all, 

 

I've been looking around the forums and trying to find an answer via search but I have been unable to thus far. I'm hoping someone can give me a hand. I'm very new to Linux and Samba but my bosses wanted me to set up a new file server on Ubuntu that can integrate with AD and have users be able to authenticate with their AD credentials. So far I have managed to get Ubuntu 16.04 installed, Kerberos configured and the system added to my AD domain. Everything is working fine. I am able to see my new file server in AD users and computers and DNS is working correctly, things are pingable and resolving right. 

 

My issue is that I am trying to use the instructions in the Samba wiki to set the share permissions and ACL on a share which I have created on my Samba server as it indicates that I shouldn't use the smb.conf to add the parameters, but instead use the Windows utilities ( https://wiki.samba.org/index.php/Setting_up_a_Share_Using_Windows_ACLs ) Unfortunately, despite everything else working correctly when I try to connect via my 2012 r2 server to the remote Samba I get an error " Computer <new server> cannot be managed. Verify hat the network path is correct, the computer is available on the network, and that the appropriate Windows Firewall rules are enabled on the target computer" Sadly, there are NO "Windows Firewall rules" since its a Ubuntu box and considering that the computer IS perfectly visible in the AD, the snap-in can find it when I 'browse', it can be ping'd and the UFW is off, I am at a loss as to what could possibly be the issue.

 

Anyone out there who has integrated a Ubuntu file server using Samba onto AD can point me in the right direction?

 

Thanks!

 

I think  that only applies to Windows systems. You are on Linux, use the smb.conf.

 

I am very shady on this, but I THINK that is what you're trying to get accross... If I'm wrong, shoot me in the foot...

@Mindovermaster I have tried both ways. Unfortunately I can't seem to get a windows user to be able to map to the samba share using only the AD credentials - which is what should be happening.  I can set up a share without the system being on the domain or using kerberos to authenticate but this is not what I am wanting. I need a ubuntu server to join my windows domain, to have users be able to map their shares using only their windows AD credentials. According to the article that I linked and the Samba wiki, this setup is completely possible - but I can't manage it. I was hoping someone had done it - and documented all the steps.

 

Thanks for trying. I think I am just going to have to set it up as a stand alone server , assign everyone their own samba passwords and have them map locally without it being a domain member.

did you validate your samba has extended ACLs enabled

 

smbd -b | grep HAVE_LIBACL

 

Does that come back that you HAVE_LIBACL?

 

If so and you joined it to the domain correctly, then yes you should be able to access via the windows tools..

 

What schema are you running you mention 2012r2 but are you actually running the 2012r2 schema -- you can check with dsquery or powershell.  Also what version of samba are you running?

 

What I can tell you off the top of my head, is yes this is very possible.. Problem is I have not done this in quite some time.. I would have to fire up some vms and run through it.

This topic is now closed to further replies.
  • Posts

    • Forza Horizon 6 gets another hotfix for one of the game's online modes by Taras Buria Recently, Forza Horizon 6 players discovered an interesting glitch that allowed farming a crazy amount of in-game credits in a few minutes. Playground Games quickly pulled the plug on the exploit by disabling one of the game's online modes, and today, the studio is rolling out another hotfix. In my review, I complained about the game still showering gamers with cars, credits, and wheelspins. As such, earning money in Forza Horizon 6 is not a particularly difficult task. You simply have to play the game, crazy, I know. However, people still found an easier path to becoming a billionaire in Forza Horizon 6. All you had to do was purchase the Hummer EV, install a specific tune, shift in reverse while going at about 15 MPH, hit a wall, and get launched into the stratosphere at the speed of light. While mid-air, launch Eliminator and quickly get eliminated. Boom, the game just awarded you with a few million in-game credits. Initially, Playground Games disabled Eliminator to prevent people from farming credits. Now, following the release of the first balancing update, developers are rolling out a new update that re-enables Eliminator and gives users a free McLaren Sabre as a gesture of goodwill. Here is the changelog: One critical issue remains unpatched, though. There are quite a few reports of the game wiping gamers' saves, and developers are still looking into that. To avoid potential data loss, Playground Games recommends taking one of the steps outlined in a previously published support article.
    • Dead by Daylight, Two Point Museum, and more join Xbox Free Play Days for the weekend by Pulasthi Ariyasinghe There is a brand-new Free Play Days offer available to Xbox players, giving them a chance to try out a new selection of games over the weekend. Microsoft's latest promotion brings some high-profile titles, including the sports title PGA TOUR 2K25 and the racing sim Assetto Corsa. Almost all the games being offered this time require an Xbox Game Pass subscription, with only one title being available for all players. Starting with the fully free-to-play section, Dead by Daylight is populating it solo. This asymmetric survival horror title should be the most familiar to most gamers, considering its age. The multiplayer four-versus-one asymmetric survival horror game has you assuming the roles of survivors or the killer to see who can come out on top. This Dead by Daylight offer will be available to play until Monday, June 22, giving you an extra day of play compared to the remainder of the Free Play Days titles. Meanwhile, Xbox Game Pass Ultimate, Premium, and Essential members can now try out the well-received tycoon game Two Point Museum, the circuit racing sim Assetto Corsa, as well as 2K's golf sim experience that gives players a career to develop alongside real-world pros and courses. Here are the announced games and the platforms they are available to play on: PGA TOUR 2K25 (Xbox Series X|S) Two Point Museum (Xbox Series X|S) Assetto Corsa (Xbox Series X|S, Xbox One) Dead by Daylight (Xbox Series X|S, Xbox One) To easily find the titles on Xbox consoles, first head to the Store, and then in the sidebar, find the Home section. In there, open the Subscriptions tab. All the games from the Free Play Days collection will show up in this section for quick access. Apart from Dead by Daylight's offer, this week's Free Play Days promotions will end on Sunday, June 21, at 11:59 pm PT.
    • Correction: Microsoft currently offers syncing through a MSA (personal) account or a Microsoft 365 work- or schoolaccount.
  • Recent Achievements

    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
    • Week One Done
      With What earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      592
    2. 2
      +Edouard
      171
    3. 3
      PsYcHoKiLLa
      75
    4. 4
      Michael Scrip
      67
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!