Project

General

Profile

Feature #3242

Enable AFP ACL support when using LDAP

Added by Aaron Oneal almost 5 years ago. Updated 12 months ago.

Status:
Closed: Not To Be Fixed
Priority:
Nice to have
Assignee:
Jordan Hubbard
Category:
-
Target version:
Estimated time:
Needs Design Doc:
No
Sprint:
Severity:
New
Backlog Priority:
Reason for Closing:
Reason for Blocked:
Needs QA:
Yes
Needs Doc:
Yes
Needs Merging:
Yes
Needs Automation:
No
Support Suite Ticket:
n/a
Hardware Configuration:

Description

ACL support for AFP shares should be enabled if LDAP is configured.

See this link:
http://netatalk.sourceforge.net/2.1/htmldocs/afp_acls.8.html

FreeNAS already has ZFS ACL passthrough configured and it has PAM setup to do LDAP authentication. But, the `afp_ldap.conf` file for Netatalk is not configured and so no mapping is performed between POSIX uid/gid and UUID for ACLs as stored in LDAP nor is `options:acls` set on shares.

The end result is, it's currently not possible to manage ACL level permissions on AFP shares using the UUID model configured in LDAP (such as OpenDirectory bundled with OS X Server).


Related issues

Related to FreeNAS - Bug #5751: AFP: unable to create folders after upgrade to 9.2.1.6Resolved2014-08-11

Associated revisions

Revision 3db65066 (diff)
Added by Josh Paetzel about 4 years ago

Add ACL support to netatalk

Ticket: #3242

History

#1 Updated by Josh Paetzel almost 5 years ago

  • Assignee set to Josh Paetzel
  • Target version set to 19

This will be taken care of as part of the planned netatalk upgrade.

#2 Updated by Jordan Hubbard over 4 years ago

  • Status changed from Unscreened to Screened

#3 Updated by Jordan Hubbard over 4 years ago

  • Target version changed from 19 to 59

#4 Updated by Josh Paetzel over 4 years ago

  • Target version changed from 59 to 49

Turns out this requires modifying the LDAP schema to work.

#5 Updated by Dennis Juhler Aagaard about 4 years ago

Hi Josh,

Can you elaborate on this?
If its on the LDAP server side something needs to be changed, maybe i can help with some scripting on the Mac OSX OD part.

-Dennis

#6 Updated by Josh Paetzel about 4 years ago

#7 Updated by Josh Paetzel almost 4 years ago

  • Related to Bug #5751: AFP: unable to create folders after upgrade to 9.2.1.6 added

#8 Updated by Josh Paetzel over 3 years ago

  • Status changed from Screened to Unscreened
  • Assignee changed from Josh Paetzel to Jordan Hubbard

#9 Updated by Jordan Hubbard about 3 years ago

  • Status changed from Unscreened to Closed: Not To Be Fixed

#10 Avatar?id=14398&size=24x24 Updated by Kris Moore 12 months ago

  • Target version changed from 49 to N/A

Also available in: Atom PDF