Authentication refused for AFP/SMB when more than 1 Share should be available
| Originator: | pepi.zawodsky | ||
| Number: | rdar://22828432 | Date Originated: | 24-Sep-2015 12:10 AM |
| Status: | Open | Resolved: | |
| Product: | OS X Server | Product Version: | 5.0.4 |
| Classification: | Serious Bug | Reproducible: | Always |
Summary: Authentication refused for AFP/SMB when more than 1 Share should be available Steps to Reproduce: In Server 5.0.4 Create: 1 User, Allow that user to use filesharing services. Create: 1 Group, assign that user to that group. Create: 2 Folders Folder A: chown user:group to the user and group you just created. Folder B: chown admin:group where admin is the local first admin User of OS X (usually uid 501) and the group is the group you just created. chmod both folders 770. Create 2 SharePoints from these folders! Assign Everyone: non, user: r/w, group r/w, no ACLs should be necessary, Spotlight can be ignored. Start File Sharing service. Try to connect to these SharePoints via AFP and SMB. Expected Results: Both SharePoints should be available to the user. Folder A: Because the user is the POSIX owner of that folder. Folder B: Because the user is in the POSIX group of that folder. Actual Results: AFP: Server refuses authentication and just shakes the password dialog. SMB: Server refuses authentication and shows a dialog that you've been denied access. Both are incorrect. The user should absolutely be allowed to access said sharepoints. This makes File Sharing completely unusable (also many other bugs apply which aid to this result. See my other RDARs on OS X Server in the past few days.) Regression: This has been mostly working in 4.1.5 and even in ASIP Server this was just fine. Notes: sysdiagnose attached.
Comments
Please note: Reports posted here will not necessarily be seen by Apple. All problems should be submitted at bugreport.apple.com before they are posted here. Please only post information for Radars that you have filed yourself, and please do not include Apple confidential information in your posts. Thank you!