Project

General

Profile

Feature #3242

Enable AFP ACL support when using LDAP

Added by Aaron Oneal over 4 years ago. Updated 7 months ago.

Status:
Closed: Not To Be Fixed
Priority:
Nice to have
Assignee:
Jordan Hubbard
Category:
-
Target version:
Start date:
10/01/2013
Due date:
% Done:

0%

Estimated time:
Severity:
Backlog Priority:
Reason for Closing:
Reason for Blocked:
Needs QA:
Yes
Needs Doc:
Yes
Needs Merging:
Yes
Needs Automation:
No
Hardware Configuration:
QA Status:
Not Tested

Description

ACL support for AFP shares should be enabled if LDAP is configured.

See this link:
http://netatalk.sourceforge.net/2.1/htmldocs/afp_acls.8.html

FreeNAS already has ZFS ACL passthrough configured and it has PAM setup to do LDAP authentication. But, the `afp_ldap.conf` file for Netatalk is not configured and so no mapping is performed between POSIX uid/gid and UUID for ACLs as stored in LDAP nor is `options:acls` set on shares.

The end result is, it's currently not possible to manage ACL level permissions on AFP shares using the UUID model configured in LDAP (such as OpenDirectory bundled with OS X Server).


Related issues

Related to FreeNAS - Bug #5751: AFP: unable to create folders after upgrade to 9.2.1.6Resolved2014-08-11

Associated revisions

Revision 3db65066 (diff)
Added by Josh Paetzel over 3 years ago

Add ACL support to netatalk

Ticket: #3242

History

#1 Updated by Josh Paetzel over 4 years ago

  • Assignee set to Josh Paetzel
  • Target version set to 19

This will be taken care of as part of the planned netatalk upgrade.

#2 Updated by Jordan Hubbard over 4 years ago

  • Status changed from Unscreened to Screened

#3 Updated by Jordan Hubbard over 4 years ago

  • Target version changed from 19 to 59

#4 Updated by Josh Paetzel over 4 years ago

  • Target version changed from 59 to 49

Turns out this requires modifying the LDAP schema to work.

#5 Updated by Dennis Juhler Aagaard over 3 years ago

Hi Josh,

Can you elaborate on this?
If its on the LDAP server side something needs to be changed, maybe i can help with some scripting on the Mac OSX OD part.

-Dennis

#6 Updated by Josh Paetzel over 3 years ago

#7 Updated by Josh Paetzel over 3 years ago

  • Related to Bug #5751: AFP: unable to create folders after upgrade to 9.2.1.6 added

#8 Updated by Josh Paetzel almost 3 years ago

  • Status changed from Screened to Unscreened
  • Assignee changed from Josh Paetzel to Jordan Hubbard

#9 Updated by Jordan Hubbard over 2 years ago

  • Status changed from Unscreened to Closed: Not To Be Fixed

#10 Avatar?id=14398&size=24x24 Updated by Kris Moore 7 months ago

  • Target version changed from 49 to N/A

Also available in: Atom PDF