
220
OES 2 SP2: Planning and Implementation Guide
n
ov
do
cx (e
n)
22
Ju
n
e 20
09
Table 21-1
POSIX vs. NSS/NCP File Security Models
Feature
POSIX / Linux
Novell Trustee Model on OES 2
Administrative
principles
Permissions are individually controlled and
managed for each file and subdirectory.
Because of the nature of the POSIX
security model, users usually have read
rights to most of the system.
To make directories and files private,
permissions must be removed.
For more information on making existing
directories private, see
Section 17.4.2,
“Providing a Private Work Directory,” on
page 196
.
Trustee assignments are made to
directories and files and flow
down from directories to
everything below unless
specifically reassigned.
Default accessibility
Users have permissions to see most of the
file system.
The contents of a few directories, such as
the
/root
home directory, can only be
viewed by the
root
user.
Some system configuration files can be
read by everyone, but the most critical files,
such as
/etc/fstab
, can only be read
and modified by
root
.
Users can see only the
directories and files for which
they are trustees (or members of
a group that is a trustee).
Home directories—an
example of default
accessibility
By default, all users can see the names of
directories and files in home directories.
During LUM installation, you can specify
that newly created home directories will be
private.
For more information on making existing
home directories private, see
Section 17.4.2, “Providing a Private Work
Directory,” on page 196
.
By default, only the system
administrator and the home
directory owner can see a home
directory. Files in the directory are
secure.
If users want to share files with
others, they can grant trustee
assignments to the individual
files, or they can create a shared
subdirectory and assign trustees
to it.
Inheritance from
parents
Nothing is inherited.
Granting permission to a directory or file
affects only the directory or file.
Rights are inherited in all child
subdirectories and files unless
specifically reassigned.
A trustee assignment can
potentially give a user rights to a
large number of subdirectories
and files.
Privacy
Because users have permissions to see
most of the file system for reasons stated
above, most directories and files are only
private when you make them private.
Directories and files are private
by default.
Summary of Contents for OPEN ENTERPRISE SERVER 2 SP2 - ADMINISTRATION
Page 4: ...4 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 14: ...14 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 24: ...24 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 26: ...26 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 76: ...76 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 80: ...80 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 82: ...82 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 98: ...98 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 122: ...122 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 148: ...148 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 178: ...178 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 208: ...208 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 216: ...216 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 224: ...224 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 232: ...232 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 234: ...234 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 242: ...242 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 244: ...244 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 248: ...248 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 252: ...252 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 256: ...256 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 276: ...276 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 278: ...278 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Page 288: ...288 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...