Dell DR2000v DR Series System Administrator Guide - Page 20

Unix Permissions Guidelines, from Windows Explorer.

Page 20 highlights

NOTE: Any user that is part of BUILTIN\Administrators can edit ACLs on CIFS shares. The local DR Series system administrator is included in the BUILTIN\Administrators group. To add additional domain groups to the BUILTIN \Administrators group, you can use the Computer Manager tool on a Windows client to connect to the DR Series system as Domain administrator and add any groups you want. This capability allows users other than the Domain administrator to modify an ACL as needed. • BUILTIN\Administrators: Allows Applies to Full access, object inherit, and container inherit. This folder, subfolders, and files. • CREATOR OWNER: Allows Full access, inherit only, object inherit, and container inherit. Applies to Subfolders and files only. • EVERYONE: Allows Applies to Traverse folders, execute files, list folders, read data, read attributes, and read extended attributes. This folder only. • NT AUTHORITY\SYSTEM: Allows Applies to Full access, object inherit, and container inherit. This folder, subfolders, and files. • BUILTIN\Users: Allows Create folders and append data, inherit-only, and container inherit. Applies to This folder, subfolders, and files. • BUILTIN\Users: Allows Applies to Read and execute, and container inherit. This folder, subfolders, and files. • BUILTIN\Users: Allows Applies to Create files and write data, object inherit, and container inherit. Subfolders only. NOTE: If these permissions are unsuitable for your needs, you can modify the default ACL to suit your own requirement using the Windows ACL Editor (for example, using Properties → Security from Windows Explorer). NOTE: The system does not understand the Owner Rights permission and sets the owner of new files/folders created by the Domain Administrators as DOM\Administrator rather than as BUILTIN\Administrators. Unix Permissions Guidelines For a user to create, delete, or rename a file or a directory requires Write access to the parent directory that contains these files. Only the owner of a file (or the root user) can change permissions. Permissions are based on the user IDs (UIDs) for the file Owner and group IDs (GIDs) for the primary group. Files have owner IDs and group owner IDs. To enable Unix access, the DR Series system supports three levels of users: • Owner (of the file) 20

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187

NOTE:
Any user that is part of BUILTIN\Administrators can edit ACLs on CIFS shares. The local DR Series system
administrator is included in the BUILTIN\Administrators group. To add additional domain groups to the BUILTIN
\Administrators group, you can use the Computer Manager tool on a Windows client to connect to the DR Series
system as Domain administrator and add any groups you want. This capability allows users other than the Domain
administrator to modify an ACL as needed.
BUILTIN\Administrators:
Allows
Full access, object inherit, and container inherit.
Applies to
This folder, subfolders, and files.
CREATOR OWNER:
Allows
Full access, inherit only, object inherit, and container inherit.
Applies to
Subfolders and files only.
EVERYONE:
Allows
Traverse folders, execute files, list folders, read data, read attributes, and read extended
attributes.
Applies to
This folder only.
NT AUTHORITY\SYSTEM:
Allows
Full access, object inherit, and container inherit.
Applies to
This folder, subfolders, and files.
BUILTIN\Users:
Allows
Create folders and append data, inherit-only, and container inherit.
Applies to
This folder, subfolders, and files.
BUILTIN\Users:
Allows
Read and execute, and container inherit.
Applies to
This folder, subfolders, and files.
BUILTIN\Users:
Allows
Create files and write data, object inherit, and container inherit.
Applies to
Subfolders only.
NOTE:
If these permissions are unsuitable for your needs, you can modify the default ACL to suit your own
requirement using the Windows ACL Editor (for example, using
Properties
Security
from Windows Explorer).
NOTE:
The system does not understand the Owner Rights permission and sets the owner of new files/folders
created by the Domain Administrators as DOM\Administrator rather than as BUILTIN\Administrators.
Unix Permissions Guidelines
For a user to create, delete, or rename a file or a directory requires Write access to the parent directory that contains
these files. Only the owner of a file (or the root user) can change permissions.
Permissions are based on the user IDs (UIDs) for the file Owner and group IDs (GIDs) for the primary group. Files have
owner IDs and group owner IDs. To enable Unix access, the DR Series system supports three levels of users:
Owner (of the file)
20