[Samba] Fileserver with Windows ACLs does not update filesystem ACL entries


on a samba fileserver which is serving shares with Windows ACLs ( configured accordingly to the wiki) I have quite often the problem, that changing the ACLs from windows do not get written to the ACLs on file system level. The security.NTACL attribute gets updated and I see the new privileges from Windows but getfacl does not show them and thus users are not able to use a directory if I give them access. The only way to resolve this is removing the security.NTACL attribute and then setting new ACLs from windows clients.

Do you have any idea how to resolve this or where to start debugging?

The server system is running debian testing with the samba version being 4.9.4-Debian


