10400455-002
©2008-14 Overland Storage, Inc.
155
SnapScale/RAINcloudOS 4.1 Administrator’s Guide
6 - Security Options
•
NFS access permissions are not cumulative
– An NFS user’s access level is based
on the permission in the NFS access list that most specifically applies. For example, if a
user connects to a share over NFS from IP address 192.168.0.1, and the NFS access for
the share gives both read-write access to “
*
” (All NFS clients) and read-only access to
192.168.0.1, the user will get read-only access.
•
Interaction between share-level and file-level access permissions
– When both
share-level and file-level permissions apply to a user action, the more restrictive of the
two applies. Consider the following examples:
Example A:
More restrictive file-level access is given precedence over more permissive
share-level access.
Example B:
More restrictive share-level access is given precedence over more permissive
file-level access.
Share Level
File Level
Result
Full control
Read-only to File A
Full control over all directories and files in SHARE1
except
where a more restrictive file-level permission
applies. The user has read-only access to File A.
Share Level
File Level
Result
Read-only
Full control to File B Read-only access to all directories and files in
SHARE1,
including
where a less restrictive file-level
permission applies. The user has read-only access
to File B.