"account unknown" on acl cannot be removed without blocking inheritence

From: David Grant (anonymous_at_discussions.microsoft.com)
Date: 01/29/04


Date: Thu, 29 Jan 2004 12:02:14 -0800

I have several folders with an "Account Unknown" entry on
the ACL that cannot be removed without turning off
inheriting permissions. However, the parent folder does
not contain that ACL entry, indicating to me that
the "Account Unknown" ACL entry is not being inherited.
My questions are:

1. Why do I need to turn off inheritence when clearly
that particular ACL entery is not being inherited?

2. Why do "Account Unknown" entries show up in the first
place and how can I easily remove them?

More info:

Our domain has never had a trust relationship. The box
in question is a DC running Windows 2000 Server SP4.
Some of the files and directories may have been copied
from an NT4 DC in the past.



Relevant Pages

  • [patch 3/3] NFSv4 ACLs on ext3
    ... +static inline int ... * The POSIX permissions are supersets of the below mask flags. ... * Compute the file mode permission bits from the file masks in the acl. ... * process matches a group class acl entry even after the result of the ...
    (Linux-Kernel)
  • Re: possible NIS/ACL bug?
    ... > entries for the two ACL added groups, but no GID seems to have ... > been stored with each entry, whereas the example in the daemon ...
    (freebsd-current)