Bug 193638

Summary: YAST2 - User Secirity - impact on Samba Server
Product: [openSUSE] SUSE Linux 10.1 Reporter: Scott Couston <scott>
Component: YaST2Assignee: Lars Müller <lmuelle>
Status: RESOLVED NORESPONSE QA Contact: Stanislav Visnovsky <visnov>
Severity: Normal    
Priority: P5 - None CC: samba-maintainers, scott, suse-beta
Version: Final   
Target Milestone: ---   
Hardware: i686   
OS: SuSE Linux 10.1   
Whiteboard:
Found By: Customer Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Scott Couston 2006-07-20 06:01:05 UTC
If File Permissions are set to secure - which directions indicate then Samba Server cannot display printers in a MS-Windows Installation. They MUST be set to easy. This contradicts help direction at side of User Security.
Comment 1 Michael Gross 2006-07-21 07:35:22 UTC
I suppose this is not a problem with YaST but with Samba.
Please provide some more information (commands, (error)messages, logs).
Comment 2 Scott Couston 2006-07-21 23:42:53 UTC
Samba functions very well. Only when restricted by user controls does it fail.
When file permissions are set to secure the work group is displayed but you are unable to expand the work group. When file permissions are set to easy the group expands to revile all printers.
Comment 3 Christian Boltz 2006-07-22 22:46:18 UTC
Do the samba logs (/var/log/samba/*) contain any relevant entries (like "permission denied")?

You can also try to find out which entry in /etc/permissions.secure causes the problem by comparing it with /etc/permissions.easy and/or manually applying the permission changes with chown and chmod (will be reset by next SuSEconfig run!).
Comment 4 Michael Gross 2006-07-24 06:37:16 UTC
Reassigning to the Samba maintainers for help.
Comment 5 Lars Müller 2006-08-02 11:46:13 UTC
Scott: About which 'file permissions' are you talking?
Comment 6 Lars Müller 2006-08-02 13:58:55 UTC
Scott: You use /etc/sysconfig/security:PERMISSION_SECURITY="secure"?

Even if set this we're able to get the list of printers.  At least with CUPS.  In this case we use libcups and no external binary.

Please provide the output of:
testparm -s --parameter-name 'printing' 2>/dev/null
Comment 7 Scott Couston 2006-08-03 13:02:11 UTC
Sorry for delay

I am using the YAST>Security and Users>Local Security

Output from Linux system follows

couston@scott:~> su
Password:
scott:/home/couston # testparm -s --parameter-name 'printing' 2>/dev/null
cups
scott:/home/couston #

End output

The problem with not being able to expand workstation printers occurs on MS-Windows when you change the YAST>Security and Users>Local Security...I can get a screen shot before and after if you like??? from a Networked MS Windows PC...give me a day or so.

If you select "Network Server" and view Details the file permissions are set to "secure" and help suggests this a a good think to have in place anyway.

The following Help is available in YAST>Security and Users>Local Security.
Quote

Other Security Settings
In this dialog, change miscellaneous settings related to local security.
File Permissions: Settings for the permissions of certain system files are set according to the data in /etc/permissions.secure or /etc/permissions.easy. Which file is used depends on this selection. Launching SuSEconfig sets these permissions according to /etc/permissions.*. This fixes files with incorrect permissions, whether this occurred accidentally or by intruders.
With Easy, most of the system files that are only readable by root in Secure are modified so other users can also read these files. Using Secure, certain system files, such as /var/log/messages, can only be viewed by the user root. Some programs can only be launched by root or by daemons, not by ordinary users. The most secure setting is Paranoid. With it, you must decide which users are able to run X applications and setuid programs.

Unquote
Comment 8 Scott Couston 2006-09-18 13:20:11 UTC
Additional info was provided on 3rd of August f this ear yet still no change in need info part. Bug has been altered now to new and re opened. If you require still more info. Please ask. I had not heard from you and accepted the need into I supplied was sufficient - however this is not the case. I have not been asked to provide more information happily

Kind Regards Scott
Comment 9 Andreas Jaeger 2006-09-18 13:48:23 UTC
Scott, it's your job to tick the box "This comment provides the needed information.  Change the status of this bug back to ASSIGNED." once you have given the information.  The developer still waits for that acknowledgement and therefore has not reacted.

I'll tick the box now for you and ask you to do so next time yourself.
Comment 10 Christoph Thiel 2008-04-25 10:00:27 UTC
Closing NOREPSONSE, due to missing information. Please retest on openSUSE   
11.0 and create a new bug report if the problem still persists.
Comment 11 Scott Couston 2008-06-03 10:54:24 UTC
????? This has major issues with without fix. To be able to use this function, it put single click at odds and for those users the should run of dingle click