NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
giox069
Mar 29, 2011Aspirant
Unable to add trusted domain user/groups to CIFS share perms
I joined my ReadyNAS NV+ (RAIDiator 4.1.7 1.00a043) to an Active Direcotry domain "MYDOMAIN". This domain is in trust relationship with another domain "TRDOMAIN". During the join phase, in the Securit...
Chevelle
Jul 01, 2011Aspirant
I am having the same issue. I have joined my ReadyNAS 2100 (RAIDiator 4.2.15) to my Active Directory domain "DOMAIN-A". I also have trust relationships with two other domains in my forest, "DOMAIN-B" ,"DOMAIN-C".
When I try to add "Write-enabled groups:" via "frontview" to my share from the other domains it strips off the domain name. For example, if I add "DOMAIN-A\IT" to the share then add "DOMAIN-B\IT" it will show "IT,IT" when it should show "DOMAIN-A\IT,DOMAIN-B\IT", correct? And to confirm my suspicion, I checked the /etc/frontview/samba/Share.conf file, And it shows:
So I trying browsing to the share in DOMAIN-B, it will not allow me to access it. But DOMAIN-A has access to it.
Now if I go in and edit the "Shares.conf" files to reflect this:
Users in "DOMAIN-A\IT" and "DOMAIN-B\IT" are able to access the share just fine.
So there must be some sort of bug in the "frontview" interface when adding users that are from different domain in the same forest.
When I try to add "Write-enabled groups:" via "frontview" to my share from the other domains it strips off the domain name. For example, if I add "DOMAIN-A\IT" to the share then add "DOMAIN-B\IT" it will show "IT,IT" when it should show "DOMAIN-A\IT,DOMAIN-B\IT", correct? And to confirm my suspicion, I checked the /etc/frontview/samba/Share.conf file, And it shows:
[IT$]
path = /c/IT$
comment = "IT Dept Share"
oplocks = 1
admin users = "admin","DOMAIN-A\dave"
write list = "@DOMAIN-A\IT","@DOMAIN-A\IT","admin"
valid users = "@DOMAIN-A\IT","@DOMAIN-A\IT","admin","nobody"
So I trying browsing to the share in DOMAIN-B, it will not allow me to access it. But DOMAIN-A has access to it.
Now if I go in and edit the "Shares.conf" files to reflect this:
[IT$]
path = /c/IT$
comment = "IT Dept Share"
oplocks = 1
admin users = "admin","DOMAIN-A\dave"
write list = "@DOMAIN-A\IT","@DOMAIN-B\IT","admin"
valid users = "@DOMAIN-A\IT","@DOMAIN-B\IT","admin","nobody"
Users in "DOMAIN-A\IT" and "DOMAIN-B\IT" are able to access the share just fine.
So there must be some sort of bug in the "frontview" interface when adding users that are from different domain in the same forest.
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!