delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2016/03/08/04:02:57

X-Recipient: archive-cygwin AT delorie DOT com
DomainKey-Signature: a=rsa-sha1; c=nofws; d=sourceware.org; h=list-id
:list-unsubscribe:list-subscribe:list-archive:list-post
:list-help:sender:date:from:to:subject:message-id:reply-to
:references:mime-version:content-type:in-reply-to; q=dns; s=
default; b=KddU+m+ctB5+TZvHFogBotY1wIiLn/CMB8nG4/gGKbV0nlG5ThXUl
lwKvZrmD2dIGtuXlGF4YWlxDvgrMU2hxoWMrU5qkE6ghfqjsI+54hG8iTI9eckjZ
mEnaN8BJX98dJ9gK/AZnQSEM4C8gW7U/vXCzEQTJOfE7GGAiVurpVg=
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=sourceware.org; h=list-id
:list-unsubscribe:list-subscribe:list-archive:list-post
:list-help:sender:date:from:to:subject:message-id:reply-to
:references:mime-version:content-type:in-reply-to; s=default;
bh=kziyHtwKJl6ux20sutLwS/n+2dA=; b=jOSFkm/4Hig31cefyQePXhwLo02x
6YfHMbEmmDomZlKjOM1zOOMsFQN7+tNMxAvjFXaMjGUGRkuiucZAj7cdaqYMSYiR
9Z+HYc7OGl26CGTK5P0MsNnf4Jp16A/usYevRB2ROEOEUSjrC+UFG5fouRAWabCN
RduTmj/TAdHodQU=
Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com
Authentication-Results: sourceware.org; auth=none
X-Virus-Found: No
X-Spam-SWARE-Status: No, score=-93.9 required=5.0 tests=BAYES_50,KAM_LAZY_DOMAIN_SECURITY,RCVD_IN_PBL,RDNS_DYNAMIC,USER_IN_WHITELIST autolearn=no version=3.3.2 spammy=H*R:U*cygwin, deny, SID, acl
X-HELO: calimero.vinschen.de
Date: Tue, 8 Mar 2016 10:02:33 +0100
From: Corinna Vinschen <corinna-cygwin AT cygwin DOT com>
To: cygwin AT cygwin DOT com
Subject: Re: Issues with ACL settings after updating to the latest cygwin.dll - correction
Message-ID: <20160308090233.GA13971@calimero.vinschen.de>
Reply-To: cygwin AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
References: <1160735037 DOT 124947226 DOT 1457200185315 DOT JavaMail DOT root AT zimbra93-e16 DOT priv DOT proxad DOT net> <1936538945 DOT 131164828 DOT 1457377923154 DOT JavaMail DOT root AT zimbra93-e16 DOT priv DOT proxad DOT net>
MIME-Version: 1.0
In-Reply-To: <1936538945.131164828.1457377923154.JavaMail.root@zimbra93-e16.priv.proxad.net>
User-Agent: Mutt/1.5.24 (2015-08-30)

--gKMricLos+KVdGMg
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Mar  7 20:12, akikij AT free DOT fr wrote:
> Hi, Corinna
>=20
> Here an example of one problematic ACL
> Here on /etc directory (here on remote system)
> [...]
> # file: .
> # owner: Unknown+User
> # group: Unknown+Group
> user::rwx
> group::r-x
> other:r-x
> default:user::rwx
> default:group::r-x
> default:other:r-x
>=20
> $ icacls .
> . NULL SID:(DENY)(Rc,S)
>   S-1-5-21-1315901005-2739448750-426064240-1000:(F)
>   S-1-5-21-1315901005-2739448750-426064240-513:(RX)
>   Tout le monde:(RX)
>   NULL SID:(OI)(CI)(IO)(DENY)(Rc,S)
>   CREATEUR PROPRIETAIRE:(OI)(CI)(IO)(F)
>   GROUPE CREATEUR:(OI)(CI)(IO)(RX)
>   Tout le monde:(OI)(CI)(IO)(RX)

I assume your machines are not in a domain?  The SIDs of that user on
the remote machine are unknown to Cygwin.  For the time being, Cygwin
can't automatically fetch SIDs on remote shares unless you're using
Active Directory.

To fix that locally you have to create /etc/passwd and /etc/group
entries for the remote accounts using `mkpasswd -l <remote machine name>'
and `mkgroup -l <remote machein name>'.  Other than that, the above
SID and it's evaluation via getfacl are perfectly valid.

> When I get Security Tab for this directory,
> Windows returns a popup message "Authorizations on etc unordered, some en=
tries may be skipped"
> After answering OK, a new panel is shown and as I click on Advanced Autor=
isations
> Windows returns a message proposing to order the ACLs.
> After ordering, I get :

Again, don't do that.  What do you want to do *exactly*?  Do you want to
change the owner and group of the file?  If so, use Cygwin's chown,
please.  Never rearrange Cygwin ACLs using non-Cygwin tools if you want
them to stay functional for the reasons outlined in my previous replies.


Corinna

--=20
Corinna Vinschen                  Please, send mails regarding Cygwin to
Cygwin Maintainer                 cygwin AT cygwin DOT com
Red Hat

--gKMricLos+KVdGMg
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCAAGBQJW3pUpAAoJEPU2Bp2uRE+gfQ0P/j/VbdLApHFWV3acCAh7m2KJ
RI2ilGcYULtaPmWWAxLt53EnD1EKhYARV832czsPBMRNo1+cON4bMDSEvJ+NdPbD
rmiCb4EK4CwGng/ofbM1EgTBQntxPEEprjs5r69exQkiQnwbiZ83Ys8TJPnv6Dwx
5FKpYCNRvNNfmB9yOpMvH15P2pcn6mxOcKYw+y6H8RJC65pdWnJwHkESHlmgNn8n
sgw2RO1NWRhdLkwZu/vPGljsX24gDt+lqyLjXzzYxPhH9qIJxKdb/var8Izv6SmE
IOhAPXeuk9up40ZkU2n2vV4qOz6HVOr3bY6EQjowTTb48hIUZLoBi7AuOdqqiT+L
B2sfzpXHdy50QZGmh/AcFXOIdWTuRLkRvSS3eYO/Z16a10vecBtjIEQ6IYv4VkdL
h60SSixDH7jFI4MRtddfLJ83bjN3toZUTJXMs6LQWkh9cNFfqneIrUaS9pFALkSG
SuvDfEC0HmD47zpuf+ykAdiDfWUqm9Fq+MXeH4fQYNuR0iP80I7DoxQ/jnru+m2a
4r+9Xv8thhasszPVPrhAylut618Dku7JGQ9Ehvi/nB7THSdbeBY9UEiTulKOdr3p
N16eBISyXqzXIuZv9k7PHLra0o7rGy7Y3xsxjeF01GpHOGApQkeq/dsib4cZ4FKD
aRluFufILJUEv8MPUuEd
=E37z
-----END PGP SIGNATURE-----

--gKMricLos+KVdGMg--

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019