Adaptec 5325301656 Administration Guide - Page 99

SnapTree Functionality, Function, Description

Page 99 highlights

SnapTrees and Security Models SnapTree Functionality The following table describes the behavior of SnapTrees and Security Models. Function Description SnapTree Directory Ownership Security Personality of Files and Directories Default ownership differs according to the method used to create the SnapTree directory: • From the client - For UNIX personality directories, the owner and owning group will be according to the logged-in user. For Windows personality directories, the owner will be the logged-in user, or "Administrators" for directories created by Domain Admins or members of the local admingrp. • From the Administration Tool - For UNIX personality directories, the user and group owner will be admin and admingrp. For Windows personality directories, the owner will be the local admingrp ("Administrators"). Files and directories created by clients inside SnapTrees will acquire security personality and permissions according to the rules of the SnapTree security model. Windows/Mixed SnapTree • Files and directories created by SMB clients will have the Windows security personality. Permissions will either be inherited according to the ACL of the parent directory (if Windows) or will receive a default ACL that grants the user full access only (if the parent is UNIX or has no inheritable permissions). • Files and directories created by non-SMB clients will have the UNIX personality. UNIX permissions will be as set by the client (per the user's local umask on the client). • The security personality of a file or directory can be changed by any user with sufficient rights to change permissions or ownership. If a client of one security personality changes permissions or ownership of a file or directory of a different personality, the personality will change to match the personality of the client protocol (e.g., if an NFS client changes UNIX permissions on a Windows file, the file will change to the UNIX personality). UNIX SnapTree • Files and directories created by non-SMB clients will have the UNIX personality. UNIX permissions will be as set by the client (per the user's local umask on the client). • Files and directories created by SMB clients will have the UNIX personality. UNIX permissions will be set to a default. • The personality of files and directories cannot be changed on a UNIX SnapTree. All files and directories always have the UNIX personality. Chapter 6 Share and File Access 85

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224

SnapTrees and Security Models
Chapter 6
Share and File Access
85
SnapTree Functionality
The following table describes the behavior of SnapTrees and Security Models.
Function
Description
SnapTree
Directory
Ownership
Default ownership differs according to the method used to create the
SnapTree directory:
From the client —
For UNIX personality directories, the owner and
owning group will be according to the logged-in user. For Windows
personality directories, the owner will be the logged-in user, or
“Administrators” for directories created by Domain Admins or members
of the local admingrp.
From the Administration Tool
— For UNIX personality directories,
the user and group owner will be admin and admingrp. For Windows
personality directories, the owner will be the local admingrp
(“Administrators”).
Security
Personality of
Files and
Directories
Files and directories created by clients inside SnapTrees will acquire
security personality and permissions according to the rules of the
SnapTree security model.
Windows/Mixed SnapTree
Files and directories created by SMB clients will have the Windows
security personality. Permissions will either be inherited according to
the ACL of the parent directory (if Windows) or will receive a default
ACL that grants the user full access only (if the parent is UNIX or has
no inheritable permissions).
Files and directories created by non-SMB clients will have the UNIX
personality. UNIX permissions will be as set by the client (per the
user’s local umask on the client).
The security personality of a file or directory can be changed by any
user with sufficient rights to change permissions or ownership. If a
client of one security personality changes permissions or ownership of
a file or directory of a different personality, the personality will change
to match the personality of the client protocol (e.g., if an NFS client
changes UNIX permissions on a Windows file, the file will change to
the UNIX personality).
UNIX SnapTree
Files and directories created by non-SMB clients will have the UNIX
personality. UNIX permissions will be as set by the client (per the
user’s local umask on the client).
Files and directories created by SMB clients will have the UNIX
personality. UNIX permissions will be set to a default.
The personality of files and directories cannot be changed on a UNIX
SnapTree. All files and directories always have the UNIX personality.