04.06.2013 Views

UCS 2.4 - Univention

UCS 2.4 - Univention

UCS 2.4 - Univention

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

4 <strong>Univention</strong> Directory Manager<br />

78<br />

This reference will be displayed on every client capable of MSDFS (e.g. Windows 2000 and XP) as a<br />

regular directory.<br />

Attention:<br />

Only restricted user groups should have write access to root directories. Otherwise, it would be pos-<br />

sible for users to redirect references to other shares, and intercept or manipulate files. In addition,<br />

paths to the shares, as well as the references are to be spelt entirely in lower case.<br />

If changes are made in the references, the concerned clients have to be restarted. Further informa-<br />

tion on this issue can be found in the Samba documentation [9] in the chapter ’Hosting a Microsoft<br />

Distributed File System Tree’.<br />

Users with write access may modify permissions<br />

According to the Unix file permission concept, only those users who own a file may change access<br />

permissions. Samba has adopted this scheme. If this option is activated, all users with write permis-<br />

sion to a file are allowed to change permissions, ACL entries, and file ownership rights. It has to be<br />

noted that users of an owner group, who merely have read permission, are not authorised to carry<br />

out any changes.<br />

Hide unreadable files/directories<br />

If this option is activated, all files which are nonreadable for the user due to their file permissions, will<br />

be hidden.<br />

’Samba permissions’ tab<br />

Samba write access<br />

Permits writing access to this share from Windows clients.<br />

Force user<br />

This username and its permissions and primary group is used for performing all the file operations<br />

of all users. The username is only used once the user has established a connection to the Samba<br />

share by using his real username and password. A common username is useful for using data in a<br />

shared way, yet improper application might cause security problems.<br />

Force group<br />

A group which is to be used by all users connecting with this share, as their primary group. Thereby,<br />

the permissions of this group automatically apply as the group permissions of all these users. A group<br />

registered here has a higher priority than a group which was assigned as the primary group of a user<br />

via the Force user entry field.<br />

If a + sign is prefixed to the group name, then the group is assigned as a primary group solely to<br />

those users which are already members of this group. All other users retain their primary groups.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!