SnapTrees and Security Models
Chapter 6 Share and File Access
85
SnapTree Functionality
The following table describes the behavior of SnapTrees and Security Models.
Function
Description
SnapTree
Directory
Ownership
Default ownership differs according to the method used to create the
SnapTree directory:
•
From the client —
For UNIX personality directories, the owner and
owning group will be according to the logged-in user. For Windows
personality directories, the owner will be the logged-in user, or
“Administrators” for directories created by Domain Admins or members
of the local admingrp.
•
From the Administration Tool
— For UNIX personality directories,
the user and group owner will be admin and admingrp. For Windows
personality directories, the owner will be the local admingrp
(“Administrators”).
Security
Personality of
Files and
Directories
Files and directories created by clients inside SnapTrees will acquire
security personality and permissions according to the rules of the
SnapTree security model.
Windows/Mixed SnapTree
• Files and directories created by SMB clients will have the Windows
security personality. Permissions will either be inherited according to
the ACL of the parent directory (if Windows) or will receive a default
ACL that grants the user full access only (if the parent is UNIX or has
no inheritable permissions).
• Files and directories created by non-SMB clients will have the UNIX
personality. UNIX permissions will be as set by the client (per the
user’s local umask on the client).
• The security personality of a file or directory can be changed by any
user with sufficient rights to change permissions or ownership. If a
client of one security personality changes permissions or ownership of
a file or directory of a different personality, the personality will change
to match the personality of the client protocol (e.g., if an NFS client
changes UNIX permissions on a Windows file, the file will change to
the UNIX personality).
UNIX SnapTree
• Files and directories created by non-SMB clients will have the UNIX
personality. UNIX permissions will be as set by the client (per the
user’s local umask on the client).
• Files and directories created by SMB clients will have the UNIX
personality. UNIX permissions will be set to a default.
• The personality of files and directories cannot be changed on a UNIX
SnapTree. All files and directories always have the UNIX personality.
Summary of Contents for 5325301656 - Snap Server 14000 NAS
Page 2: ......
Page 76: ...Disks and Units 62 Snap Server Administrator Guide ...
Page 92: ...Creating iSCSI Disks 78 Snap Server Administrator Guide ...
Page 108: ...Security Guides 94 Snap Server Administrator Guide ...
Page 144: ...Unicode and Expansion Arrays 130 Snap Server Administrator Guide ...
Page 164: ...Off the Shelf Backup Solutions for the Snap Server 150 Snap Server Administrator Guide ...
Page 172: ...Scripts in SnapCLI 158 Snap Server Administrator Guide ...