gostaria de saber como proteger umarquivo apos ele ser aberto por um outro 
usuario ou seja quando um usuario abrir um determinado arquivo, se caso um 
outro usuario for abrir o mesmo, estaja disponivel em somente leitura 
Obrigado 
a minha versao do samba é 3 
segue meu smb.conf 

[global]
workgroup = xxx
netbios name = xxx
server string = xxx
security = user
encrypt passwords = yes
load printers = yes
log file = /var/log/samba/%m.log
max log size = 50
os level = 100
local master = yes
domain master = yes
preferred master = yes
domain logons = yes
admin users = xxxxx
logon script = xxxx
logon path = \\%L\profiles\%U
wins support = no
lanman auth = Yes
ntlm auth = Yes
client NTLMv2 auth = Yes
client lanman auth = No
client plaintext auth = No
winbind separator = +
winbind use default domain = Yes
winbind uid =10000-20000
winbind gid =10000-20000
winbind enum users = yes
winbind enum groups = yes
password server= xxxx
lock directory = /usr/local/samba/var/locks/
dns proxy = no
ldap passwd sync = yes
ldap delete dn = Yes
passdb backend = ldapsam:ldap://127.0.0.1/
ldap admin dn = cn=xxx,dc=xx,dc=xx,dc=xx
ldap suffix = dc=xxx,dc=xx,dc=xx
ldap group suffix = ou=Grupos
ldap user suffix = ou=Usuarios
ldap machine suffix = ou=Computadores
idmap uid = 10000-15000
idmap gid = 10000-15000
nt acl support = yes
map acl inherit = Yes
inherit acl = Yes
inherit permissions = Yes
passwd chat = *New*password* %n  *Retype*new*password* %n 
*passwd:*all*authentication*tokens*updated*successfully*
socket options = TCP_NODELAY IPTOS_LOWDELAY SO_RCVBUF=8192 SO_SNDBUF=8192
add machine script = /usr/local/sbin/smbldap-useradd -w "%u"
add user script = /usr/local/sbin/smbldap-useradd -m "%u"
delete user script = /usr/local/sbin/smbldap-userdel "%u"
add machine script = /usr/local/sbin/smbldap-useradd -w "%u"
add group script = /usr/local/sbin/smbldap-groupadd -p "%g"
delete group script = /usr/local/sbin/smbldap-groupdel "%g"
add user to group script = /usr/local/sbin/smbldap-groupmod -m "%u" "%g"
delete user from group script = /usr/local/sbin/smbldap-groupmod -x "%u" "%g"
set primary group script = /usr/local/sbin/smbldap-usermod -g "%g" "%u"
#dos charset = UTF-8
#unix charset = UTF-8
dos filetimes = Yes
character set = ISO8859-1
client code page = 850
preserve case = no
short preserve case = no
hide unreadable = yes
default case = lower
cups server = xxx

[homes]
#root preexec = /usr/bin/mkdir.sh "/home/users/%u" "%u" "%g"
comment = Diretorio Home
path = /home/users/%u
browseable = no
writable = yes
guest ok = no
read only = no
create mask = 0700
directory mask = 0700

[profiles]
path = /home/profiles/
read only = no
browseable = no
writable = yes
guest ok = no
profile acls = yes
csc policy = disable
create mask = 0700
directory mask = 0700
force user = %U

[netlogon]
path = /home/netlogon
public = no
browseable = no
writable = no
read only = yes

[printers]
comment = Impressoras
path = /var/spool/samba
browseable = no
guest ok = no
writable = no
printable = yes

[publico]
comment = Area Publica
path = /home/publico/
browseable = yes
guest ok = yes
writable = yes
read only = no
create mask = 0777
directory mask = 0777
force user = %U
force group = %G

[grupos]
comment = Grupos
path = /home/grupos/%G
browseable = no
guest ok = no
writable = yes
read only = no
create mask = 0770
directory mask = 0770
force user = %U
force group = %G

[teste] ( aki esta meu problema ) 
comment = teste
path = /home/xx
browseable = yes
guest ok = no
public = no
writable = yes
read only = no
locking = yes
locking = 1
posix locking = yes
read prediction = Yes
read raw = yes
share modes = yes

[antivirus]
comment = Antivirus
path = /home/antivirus
browseable = no
guest ok = yes
writable = no
readonly = yes
public = yes

---------------------------------------------------------------------------
Esta lista é patrocinada pela Conectiva S.A. Visite http://www.conectiva.com.br

Arquivo: http://bazar2.conectiva.com.br/mailman/listinfo/linux-br
Regras de utilização da lista: http://linux-br.conectiva.com.br
FAQ: http://www.zago.eti.br/menu.html

Responder a