home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!crdgw1!newsun!novell.com!keith
- From: keith@novell.com (Keith Brown)
- Newsgroups: comp.sys.novell
- Subject: Re: NFS<->NetWare permissions...help!!!
- Summary: nfs to netware permissions...help
- Message-ID: <keith.12.0@novell.com>
- Date: 12 Jan 93 21:52:17 GMT
- References: <mtsjej.726857335@gsusgi1.gsu.edu>
- Sender: news@novell.com (The Netnews Manager)
- Organization: Connectivity Products Division, Novell Inc.
- Lines: 47
- Nntp-Posting-Host: keith2.sjf.novell.com
-
- In article <mtsjej.726857335@gsusgi1.gsu.edu> mtsjej@gsusgi2.gsu.edu (slug) writes:
- >NetWare Server----
- >Server/GEN:
- > Supervisor [SRW M A] **I WANT [SRWECMFA]
- > NoGroup [ RW ] **I WANT [ ]
- > Everyone [ RW ] **I WANT [ ]
-
- First point, NOGROUP should not really end up as a group trustee of a
- file/directory when things are configured properly. You should map your UNIX
- groups to NetWare groups using NFSADMIN and initialise your exported file
- systems files and directories to be owned by "proper" mapped groups.
-
- Apart from that, what I believe is confusing you is NetWare NFS not removing
- READ or WRITE trustee rights from the group trustee derived from the files
- group owner or the EVERYONE group trustee corresponding to the NFS permissions
- for "other". The reason for this is NetWare NFS's inability to determine
- whether or not these rights actually were put there by itself during some
- previous NFS SETATTR operation. You see, they might have been put there by
- something else on the DOS side and probably for good reason. We are unable to
- make assumptions like that and thus what NetWare NFS giveth in this area
- (or what it may have giveth!), it can not taketh away, just in case! One of
- our axioms for not violating NetWare security with NetWare NFS is that UNIX
- users/groups will only have less than or equal privilege on the NetWare file
- system to the NetWare/DOS users/groups to which they have been mapped. This is
- one of the potential "less than" cases.
-
- It actually isn't as complicated as it sounds. If you stick with a UNIX/NFS
- view of the NetWare file system then you will see just that and no confusion
- should result. If you stick with a DOS/NetWare view of the file system then
- you'll see just that, perhaps with more trustees than you're used to seeing
- but what the hey. It's only when you twiddle with things on the UNIX side and
- rush over to the DOS side to see what's happened *or* twiddle with things on
- the DOS/NetWare side and rush over to UNIX to see what's happened that NetWare
- NFS will start messing with your head. To explain what you are looking at
- requires you to have a *complete* understanding of the semantics of both
- NetWare and UNIX/NFS file systems (and I do mean the semantics here. Just
- knowing what r, w and x are on UNIX file systems and what SRWECFMA are on
- NetWare file systems isn't enough. You have to think about what these things
- really mean.). My experience has been that such animals are a tad rare.
- However, rest assured that there is a reason for it all and it's all in the
- name of security! :-)
-
- Keith
- -
- Keith Brown Phone: 408-473-8308
- Novell San Jose Development Center Fax: 408-473-8990
- 2180 Fortune Drive, San Jose, CA 95131 Net: keith@sjf.novell.COM
-