SnapTrees and Security Models
Chapter 6 Share and File Access
101
SnapTree Functionality
The following table describes the behavior of SnapTrees and Security Models.
Function
Description
SnapTree
Directory
Ownership
Default ownership differs according to the method used to create the
SnapTree directory:
•
From the client —
For UNIX personality directories, the owner and
owning group will be according to the logged-in user. For Windows
personality directories, the owner will be the logged-in user, or
“Administrators” for directories created by Domain Admins or members
of the local admingrp.
•
From the Administration Tool
— For UNIX personality directories,
the user and group owner will be admin and admingrp. For Windows
personality directories, the owner will be the local admingrp
(“Administrators”).
Security
Personality of
Files and
Directories
Files and directories created by clients inside SnapTrees will acquire
security personality and permissions according to the rules of the
SnapTree security model.
Windows/Mixed SnapTree
• Files and directories created by SMB clients will have the Windows
security personality. Permissions will either be inherited according to
the ACL of the parent directory (if Windows) or will receive a default
ACL that grants the user full access only (if the parent is UNIX or has
no inheritable permissions).
• Files and directories created by non-SMB clients will have the UNIX
personality. UNIX permissions will be as set by the client (per the
user’s local umask on the client).
• The security personality of a file or directory can be changed by any
user with sufficient rights to change permissions or ownership. If a
client of one security personality changes permissions or ownership of
a file or directory of a different personality, the personality will change
to match the personality of the client protocol (e.g., if an NFS client
changes UNIX permissions on a Windows file, the file will change to
the UNIX personality).
UNIX SnapTree
• Files and directories created by non-SMB clients will have the UNIX
personality. UNIX permissions will be as set by the client (per the
user’s local umask on the client).
• Files and directories created by SMB clients will have the UNIX
personality. UNIX permissions will be set to a default.
• The personality of files and directories cannot be changed on a UNIX
SnapTree. All files and directories always have the UNIX personality.
Summary of Contents for 5325301507 - Snap Server 4400 NAS
Page 2: ......
Page 12: ...xii SnapServer Administrator Guide ...
Page 16: ...xvi SnapServer Administrator Guide ...
Page 58: ...Print Server 42 SnapServer Administrator Guide ...
Page 64: ...NIS Domain 48 SnapServer Administrator Guide ...
Page 110: ...Configuring VSS VDS for iSCSI Disks 94 SnapServer Administrator Guide ...
Page 154: ...Log View 138 SnapServer Administrator Guide ...
Page 228: ...Phone Home Support 212 SnapServer Administrator Guide ...