[rsbac] rsbac + ldap/samba

Alexander Bokovoy ab at altlinux.org
Thu Jan 12 15:28:22 CET 2006

Amon Ott wrote:
> With RSBAC CAP module we could easily allow setuid no matter what uid
>  samba has. Would this be an acceptable solution?
May be, though this needs testing.

> Would you be willing to help, if someone tried to create such a 
> solution? We already have ang-st creating RSBAC modules for apache, 
> he might be interested.
That is of a particular interest for me, yes.

> AFAIU, the RSBAC ACL module provides a superset of Windows Network 
> ACLs (if not, we can extend it), so it should be possible to have 
> full Windows managed ACLs on Samba with it.
That might be an interesting thing to do on Samba 4 code which allows
much easier replacement of modules (including ACLs).

/ Alexander Bokovoy
Samba Team                      http://www.samba.org/
ALT Linux Team                  http://www.altlinux.org/
Midgard Project Ry              http://www.midgard-project.org/

More information about the rsbac mailing list