background image

Managing File Security

33

no

vd

ocx (

E

NU)

  

01

 F

ebr
ua

ry 
200
6

5.2  Changing Trustee Rights

The assignment of rights involves a trustee and a target object. The trustee represents the user or set 
of users that are receiving the authority. The target represents those network resources the users have 
authority over. You must have the Access Control right to change trustee assignments.

1

In a file manager, right-click a Novell file system directory or file.

2

Do one of the following: 

• GNOME: 

Click 

Novell Properties

.

• KDE: 

Click 

Actions > Novell Properties

.

3

Click the 

Novell Rights

 tabbed page. 

4

In the 

Trustees

 list, select the trustee whose rights you want to change.

5

Select or deselect the rights you want to assign for this trustee. 
For each trustee in the list, there is a set of eight check boxes, one for each right that can be 
assigned. If a check box is selected, the trustee has that right. The following rights can be set 
for each trustee:

• Read: 

For a directory, grants the right to open files in the directory and read the contents 

or run the programs. For a file, grants the right to open and read the file.

• Write: 

For a directory, grants the right to open and change the contents of files in the 

directory. For a file, grants the right to open and write to the file.

• Erase: 

Grants the right to delete the directory or file.

• Create: 

For a directory, grants the right to create new files and directories in the directory. 

For a file, grants the right to create a file and to salvage a file after it has been deleted.

• Modify: 

Grants the right to change the attributes or name of the directory or file, but does 

not grant the right to change its contents (changing the contents requires the Write right).

• File  Scan: 

Grants the right to view directory and file names in the file system structure, 

including the directory structure from that file to the root directory.

• Access Control: 

Grants the right to add and remove trustees for directories and files and 

modify their trustee assignments and Inherited Rights Filters.

• Supervisor: 

Grants all rights to the directory or file and any subordinate items. The 

Supervisor right can’ be blocked by an Inherited Rights Filter. Users with this right can 
grant or deny other users rights to the directory or file.

6

Click 

OK

Trustee assignments override inherited rights. To change an Inherited Rights Filter, click 

Inherited 

Rights and filter

s.

5.3  Adding a Trustee

When you add a trustee to a Novell file system directory or file, you grant a user (the trustee) rights 
to that directory or file.You must have the Access Control right to add a trustee.

1

In a file manager, right-click the Novell file or directory that you want to add a trustee to.

2

Do one of the following: 

• GNOME: 

Click 

Novell Properties

.

Summary of Contents for CLIENT FOR LINUX 1.2

Page 1: ...Novell w w w n o v e l l c o m novdocx ENU 01 February 2006 Novell Client for Linux 1 2 Administration Guide Client TM for Linux 1 2 J u l y 2 6 2 0 0 6 A D M I N I S T R A T I O N G U I D E...

Page 2: ...export or import deliverables You agree not to export or re export to entities on the current U S export exclusion lists or to any embargoed or terrorist countries as specified in the U S export laws...

Page 3: ...ll Trademarks For Novell trademarks see the Novell Trademark and Service Mark list http www novell com company legal trademarks tmlist html Third Party Materials All third party trademarks are the pro...

Page 4: ...novdocx ENU 01 February 2006...

Page 5: ...r Settings 19 3 1 6 Configuring OpenSLP Settings 21 3 2 Using Configuration Files to Preconfigure the Novell Client 22 4 Managing Login 25 4 1 Setting Up Integrated Login 25 4 1 1 Installing and Enabl...

Page 6: ...ovell Client Virtual File System Kernel Module 43 A 1 Installing the Required Packages 43 A 2 Compiling the Novell Client Virtual File System Kernel Module 44 A 2 1 Compiling the Novell Client Virtual...

Page 7: ...ation included with this product Please use the User Comments feature at the bottom of each page of the online documentation or go to www novell com documentation feedback html and enter your comments...

Page 8: ...8 Novell Client for Linux 1 2 Administration Guide novdocx ENU 01 February 2006...

Page 9: ...ature that allows login profiles to be stored for use by subsequent network login operations This functionality makes use of CASA Common Authentication Services Adapter for persistent storage of crede...

Page 10: ...10 Novell Client for Linux 1 2 Administration Guide novdocx ENU 01 February 2006...

Page 11: ...smoothly Installation and Upgrades The Novell Client for Linux can be installed and upgraded using either YaST or an installation script For more information see the Novell Client for Linux 1 2 Insta...

Page 12: ...he Novell Client loads a single binary that works on multiple operating system platforms without modifications The Novell Client for Linux has a Virtual File System that consists of a kernel module no...

Page 13: ...Virtual File System Kernel Module on page 43 NOTE If you patch the kernel for any reason you must make sure that you have the required packages that correspond to the kernel patch For a list of the re...

Page 14: ...14 Novell Client for Linux 1 2 Administration Guide novdocx ENU 01 February 2006...

Page 15: ...ge 15 Using Configuration Files to Preconfigure the Novell Client page 22 3 1 Using the Novell Client Configuration Wizard The Novell Client for Linux includes a Novell Client Configuration Wizard to...

Page 16: ...re then used by the Novell Client IMPORTANT When the Novell Client software is uninstalled these settings are not saved 3 1 1 Configuring Login Settings Use the Login Settings page in the Novell Clien...

Page 17: ...to This setting is overridden by the Login Dialog Context history For more information on using the Novell Login dialog box see Logging In to the Network in the Novell Client for Linux User Guide 3 1...

Page 18: ...ice Location Protocol queries SLP for eDirectoryTM and Bindery names NCP Signature Level Specify the level of enhanced security support Enhanced security includes the use of a message digest algorithm...

Page 19: ...Page This page contains the following options Launch Tray Application Select this option to automatically launch the Novell Client Tray Application Tray Application Menu Options Enables or disables th...

Page 20: ...n when users right click a Novell file system directory or file in a file manager File and Folder Information Enables or disables the File Information and Folder Information tabs on the File and Folde...

Page 21: ...rectory agent DA must support Directory Agent List Specify the specific DAs that UA and SA agents must use If this setting is not used dynamic DA discovery is used to determine which DAs to use Broadc...

Page 22: ...for Windows Installation and Administration Guide for more information Preconfiguring the Novell Client for Linux requires the novell client conf spec file and the make_novell client conf_rpm Bash scr...

Page 23: ...aST Add the location of the newly created novell client conf version_number platform rpm to the list of installation sources in YaST add a local directory in the Installation Source option and point i...

Page 24: ...24 Novell Client for Linux 1 2 Administration Guide novdocx ENU 01 February 2006...

Page 25: ...root user and the integrated login feature does not work if a workstation is set up to not ask for a password in the display manager greeter For integrated login to work the Novell Common Authenticat...

Page 26: ...ME Click Computer More Applications YaST Control Center SUSE Linux 10 1 GNOME Click Desktop YaST KDE Click the menu button System YaST Control Center 2 Click Security and Users in the left column then...

Page 27: ...in the dialog based on the saved settings 7 Optional Click Clear Profile to remove the profile settings 8 Click OK to log in to the server specified in Step 3 4 1 3 Managing System Wide Integrated Lo...

Page 28: ...s platform you should customize the scripts to optimize workstation login to your network For more information on setting up login scripts see the Novell Login Scripts Guide 4 3 Setting Up Login Restr...

Page 29: ...des a Novell Client Configuration Wizard to simplify the process of configuring your SLP and other Novell Client configuration options The Novell Client Configuration Wizard provides only basic SLP co...

Page 30: ...integer giving the maximum number of results to accumulate and return for a synchronous request before the time out or the maximum number of results to return through a callback if the request results...

Page 31: ...the Read Only attribute This also occurs if you copy files from one server to another using any method other than NCOPY at the command terminal For more information on the specific rights on NetWare a...

Page 32: ...older Users can receive rights in a number of ways such as explicit trustee assignments inheritance and security equivalence see eDirectory Rights Concepts http www novell com documentation edir873 ed...

Page 33: ...rase Grants the right to delete the directory or file Create For a directory grants the right to create new files and directories in the directory For a file grants the right to create a file and to s...

Page 34: ...ires the Write right File Scan Grants the right to view directory and file names in the file system structure including the directory structure from that file to the root directory Access Control Gran...

Page 35: ...n rights to both FILEA and FILEB Her Access Control right is lost because the combined rights are based on the rights given to Michael Nancy has Read and File Scan rights to both FILEA and FILEB She h...

Page 36: ...36 Novell Client for Linux 1 2 Administration Guide novdocx ENU 01 February 2006...

Page 37: ...s supported via SSL and Simple Bind protocol Servers devices and or services are authenticated Yes Connections to servers are authenticated via user supplied credentials No device authentication is su...

Page 38: ...on of packet signing Packet signing is enabled by default FIPS 140 2 compliant No This product currently uses the ATB authentication toolbox instead of Novell s NICI product Therefore this product is...

Page 39: ...gether to compare ACLs for a given file system path or object retrieved from eDirectory to the identity and session scope established for the identity that owns a given connection The VFS acts as a pr...

Page 40: ...gin configuration file All fields in the Novell Login dialog box except the password are stored in this file HOME novell ncl MapDrives conf This user configuration file specifies the drive mapping to...

Page 41: ...DE startup for ncl_autologin HOME gnome2 session manual X GNOME startup for ncl_autologin opt novell ncl bin ncl_autologin X Validates and run nwlogin or gnwlogin opt novell ncl bin nwlogin This exist...

Page 42: ...be compromised For example if a malicious entity gets root access it might be able to steal user credentials and authenticate to the network with those credentials File New Modified Description opt n...

Page 43: ...e installation failed you do not need to repeat this step 3 Compile the Novell Client Virtual File System Kernel Module See Section A 2 Compiling the Novell Client Virtual File System Kernel Module on...

Page 44: ...r all the packages have been installed click Close to close the YaST Control Center A 2 Compiling the Novell Client Virtual File System Kernel Module Depending on whether or not you have a standard ke...

Page 45: ...custom kernel 1 In a terminal log in as root 2 Unpack the proc config gz file and copy the resulting config to the new name usr src linux config 3 In the usr src linux directory enter the following co...

Page 46: ...46 Novell Client for Linux 1 2 Administration Guide novdocx ENU 01 February 2006...

Page 47: ...the opt novell ncl bin directory and include the following Section B 1 Shell Commands on page 47 Section B 2 GUI Utilities on page 48 B 1 Shell Commands Table B 1 The Novell Client for Linux Shell Com...

Page 48: ...following ncl_man utility_name For example ncl_man ncl_tray map Creates a mapping mount from a local file system to a remote file system on a Novell file server map d drive s server v volume f filesp...

Page 49: ...ys to move up and down Use the Home and End keys to move between the beginning and the end of a document To exit a man page press q You can learn more about the man command by entering man man in a te...

Page 50: ...50 Novell Client for Linux 1 2 Administration Guide novdocx ENU 01 February 2006...

Page 51: ...to the documentation The documentation was updated on the following dates Section C 1 July 26 2006 on page 51 Section C 2 December 23 2005 on page 51 C 1 July 26 2006 Removed Novell Linux Desktop 9 an...

Reviews: