I would set the the share level ACL such that everyone has read access. CIFS should respect the most restrictive permissions so any file that was writable by the WAFL permission bits (in this case UNIX permission bits) should be over-ridden by the share-level ACL.