ONTAP Discussions

cDOT 8.2.1RC2 not accepting "Everyone" for CIFS share ACL

mark_schuren
4,728 Views

Hi community!

I've recently upgraded our lab cluster to 8.2.1RC2 (from 8.2P5).

Now I try this:

labcm01::> cifs share access-control create -vserver vsasupdata -share test2 -user-or-group Everyone -permission Full_Control

Gives me:

Error: command failed: Failed to resolve the security identifier (SID) for the account named "Everyone". Reason: Bad user 'Everyone' or domain ''.

Is anyone else seeing this? I'm pretty sure this worked before in 8.2.0...

When I create a new share the default is "Everyone Full_Control", however if I change that to a diffwerent user/group (delete Everyone) and later want to change it back, it looks impossible.

Ideas? Or better Burt ID?

3 REPLIES 3

MARIOWEISE
4,728 Views

Hi,

we've had the exact same issue, new shares worked with everyone, manually adding everyone to existing shares didn't. What language is your domain? We had a german domain and had to use "Jeder" with Clustered ONTAP 8.2.1rc1. Since "Jeder" doesn't work with the old 7-Mode systems in the same domain, we have to migrate all "everyone" share access manually

Regards

Mario

bloehlein
4,728 Views

Hi Mark,

currently cDOT won't translate well-known users and groups directly, so you would have to use the local equivalent, e.g. Jeder in a german domain for everyone. Sadly this will brick transitions using 7MTT since share-acls often use Everyone, Domain Users, Domain Administrators and other well-known identifiers.

Please attach your systems to Bug 803576.

Best regards,

Bernd

mark_schuren
4,728 Views

Yes that's it. Breaks my 7MTT migration as well. Thanks for the tip.

Public