Red Hat NETSCAPE ENTREPRISE SERVER 6.0 - ADMINISTRATOR Specifications Page 121

  • Download
  • Add to my manuals
  • Print
  • Page
    / 250
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 120
Configuring Share Access
Chapter 6 Share and File Access 105
Configuring Share Access
The GuardianOS supports share-level as well as file- and directory-level
permissions (see “Windows ACLs” on page 107) for all local and Windows domain
users and groups.
Share Access Behaviors
Administrators tasked with devising security policies for the SnapServer will find
the following share access behaviors of interest:
Share access defaults to full control — The default permission granted to users
and groups when they are granted access to the share is full control. You may
restrict selected users and groups to read-only access.
User-based share access permissions are cumulative — An SMB, AFP, HTTP, or
FTP user's effective permissions for a resource are the sum of the permissions
that you assign to the individual user account and to all of the groups to which
the user belongs in the Share Access page. For example, if a user has read-only
permission to the share, but is also a member of a group that has been given full-
access permission to the share, the user gets full access to the share.
NFS access permissions are not cumulative — an NFS user's access level is based
on the permission in the NFS access list that most specifically applies. For
example, if a user connects to a share over NFS from IP address 192.168.0.1, and
the NFS access for the share gives read-write access to
* (All NFS clients) and
read-only access to 192.168.0.1, the user will get read-only access.
Interaction between share-level and file-level access permissions — When both
share-level and file-level permissions apply to a user action, the more restrictive
of the two applies. Consider the following examples:
Example A: More restrictive file-level access trumps more permissive share-level
access.
Share Level File Level Result
Full control Read-only to FileA Full control over all directories and files in
SHARE1 except where a more restrictive file-level
permission applies. The user has read-only
access to FileA.
Page view 120
1 2 ... 116 117 118 119 120 121 122 123 124 125 126 ... 249 250

Comments to this Manuals

No comments