[Freeipa-users] File user and group ownership listings...
Simpson Lachlan
Lachlan.Simpson at petermac.org
Thu May 19 22:55:42 UTC 2016
> -----Original Message-----
> From: freeipa-users-bounces at redhat.com [mailto:freeipa-users-
> bounces at redhat.com] On Behalf Of Alexander Bokovoy
> Sent: Thursday, 19 May 2016 5:12 PM
> To: Lachlan Musicman
> Cc: freeipa-users at redhat.com
> Subject: Re: [Freeipa-users] File user and group ownership listings...
>
> On Thu, 19 May 2016, Lachlan Musicman wrote:
> >Now that groups are working as expected, we have noticed that when
> >listing a directory the user and group now have full domain qualifiers.
> >
> >This doesn't look great. We've also noticed that we now need to
> >
> >chown :group at subdomain filename
> >
> >(with default_domain_suffix set).
> >
> >
> >Is there a reason why when the group's name and ID is the same across
> >both domains, it can't be considered the same group for file ownership reasons?
> In POSIX systems user and group IDs are two different namespaces. We force
> so-called private groups to have the same ID as the user to simplify some of hard
> identity mapping problems between POSIX and Windows environments. In
> Windows world security identifier (SID) namespace is the same for all objects.
Ah, ok then. Thanks!
Cheers
L.
This email (including any attachments or links) may contain
confidential and/or legally privileged information and is
intended only to be read or used by the addressee. If you
are not the intended addressee, any use, distribution,
disclosure or copying of this email is strictly
prohibited.
Confidentiality and legal privilege attached to this email
(including any attachments) are not waived or lost by
reason of its mistaken delivery to you.
If you have received this email in error, please delete it
and notify us immediately by telephone or email. Peter
MacCallum Cancer Centre provides no guarantee that this
transmission is free of virus or that it has not been
intercepted or altered and will not be liable for any delay
in its receipt.
More information about the Freeipa-users
mailing list