12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Using Access Control Lists 187. For an individual user:u::. For a specific user group:g::. For users not in the user group associated with the file:o:. Via the effective rights mask:m:The first three rule types (individual user, user group, or users not in the user group forthe file) are pretty self-explanatory. They allow you to give read, write, or execute permissionsto users in these three categories. A user or group ID may be used, or the actual usernameor group name.CAUTIONIf the actual username or group name is used to set an ACL, the UID or GID for it arestill used to store the ACL. If the UID or GID for a user or group name changes, theACLs are not changed to reflect the new UID or GID.But, what is the effective rights mask? The effective rights mask restricts the ACL permissionset allowed for users or groups other than the owner of the file. The standard filepermissions are not affected by the mask, just the permissions granted by using ACLs. Inother words, if the permission (read, write, or execute) is not in the effective rights mask,it appears in the ACLs retrieved with the getfacl command, but the permission isignored. Listing 7.11 shows an example of this where the effective rights mask is set toread-only, meaning the read-write permissions for user brent and the group associatedwith the file are effectively read-only. Notice the comment to the right of the ACLsaffected by the effective rights mask.7LISTING 7.11Effective Rights Mask# file: testfile# owner: tammy# group: tammyuser::rwuser:brent:rwgroup::rwmask::r--other::rw-#effective:r--#effective:r--The effective rights mask must be set after the ACL rule types. When an ACL for an individualuser (other than the owner of the file) or a user group is added, the effective rights

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!