无法删除Samba服务器的奇怪ACL
我有一个Samba共享目录// DC/DOCUMENTS。但是,它具有奇怪的ACL ACL:S-1-22-2-0:允许/0x0/
,我可以看到但无法删除。
在这里,您可以看到它已正确列出,但没有用户名
$ smbcacls //dc/documents / -U "MYDOMAIN\admin"
Password for [MYDOMAIN\admin]:
REVISION:1
CONTROL:SR|DP
OWNER:MYDOMAIN\Domain Users
GROUP:MYDOMAIN\Domain Users
ACL:Everyone:ALLOWED/OI|CI/
ACL:CREATOR OWNER:ALLOWED/OI|CI|IO/FULL
ACL:CREATOR GROUP:ALLOWED/OI|CI|IO/READ
ACL:S-1-22-2-0:ALLOWED/0x0/
ACL:MYDOMAIN\Domain Users:ALLOWED/OI|CI/FULL
,当我尝试删除它时,会发生强大的错误
$ smbcacls //dc/documents / -U "MYDOMAIN\admin" -D "ACL:S-1-22-2-0:ALLOWED/0x0/ "
Password for [MYDOMAIN\admin]:
ACE 'S-1-22-2-0:ALLOWED/0x0/ ': bad permission value at ' '
,但是删除 /添加其他ACL没有任何问题。而且我怀疑由于这个奇怪的ACL,我什至无法从窗户上更改ACL。如果我单击“共享目录”的属性对话框的“安全性”选项卡,它将仅崩溃。
现在我被困在这里,有什么想法吗?谢谢!
I have a samba shared directory //dc/documents. However it has strange ACL ACL:S-1-22-2-0:ALLOWED/0x0/
which I can see but cannot delete.
here you can see it's listed properly but without a user name
$ smbcacls //dc/documents / -U "MYDOMAIN\admin"
Password for [MYDOMAIN\admin]:
REVISION:1
CONTROL:SR|DP
OWNER:MYDOMAIN\Domain Users
GROUP:MYDOMAIN\Domain Users
ACL:Everyone:ALLOWED/OI|CI/
ACL:CREATOR OWNER:ALLOWED/OI|CI|IO/FULL
ACL:CREATOR GROUP:ALLOWED/OI|CI|IO/READ
ACL:S-1-22-2-0:ALLOWED/0x0/
ACL:MYDOMAIN\Domain Users:ALLOWED/OI|CI/FULL
and when I try to delete it a strong error occurs
$ smbcacls //dc/documents / -U "MYDOMAIN\admin" -D "ACL:S-1-22-2-0:ALLOWED/0x0/ "
Password for [MYDOMAIN\admin]:
ACE 'S-1-22-2-0:ALLOWED/0x0/ ': bad permission value at ' '
However deleting / adding other ACLs do not have any problem. And I suspect because of this strange ACL, I cannot even change the ACLs from Windows either. It would simply crash explorer if I click on the "Security" tab of the shared directory's properties dialog.
Now I'm stuck here, any thoughts? Thanks!
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
为域管理用户做一个 - 设置。
您应该删除所有ACL并从头开始。
这将在文件夹的“安全性”选项卡中修复Windows锁定。
Do a --set for the domain admin user.
You should delete all ACL's and start from scratch.
This fixes the windows lock in the security tab for the folder.