630 likes | 776 Views
File System Security. Gary DeRoest. Topics. Access Rights Security Trustee Effective Rights Inherited Rights Inherited Rights Filter Tools Attribute Security Documentation. Access Rights Security. Access to shared directories and files Securing sensitive data Drop boxes
E N D
File System Security Gary DeRoest
Topics • Access Rights Security • Trustee • Effective Rights • Inherited Rights • Inherited Rights Filter • Tools • Attribute Security • Documentation
Access Rights Security • Access to shared directories and files • Securing sensitive data • Drop boxes • Executing programs • Viewing directory contents
Access Rights Security • Supervisor Access Right • Directory • Grants all rights • Cannot be blocked by IRF or reassigned • File • Grants all rights to specified file S
Access Rights Security • Read Access Right • Directory • Read files or run programs within specified directory • File • Read or run specified file R
Access Rights Security • Write Access Right • Directory • Allows users to add or change data to files in this directory • File • Users can add or chance data to specified file W
Access Rights Security • Create Access Right • Directory • Users can create files and subdirectories in specified directory • File • Users can salvage specified file if deleted C
Access Rights Security • Erase Access Right • Directory • Allows users to delete files and destroy subdirectories • File • Allow user to delete specified file E
Access Rights Security • Modify Access Right • Directory • Allows users to change file and subdirectory names as well as attribute settings • File • Allow user to change name or attribute settings for specified file M
Access Rights Security • File Scan Access Right • Directory • Allows users to view file and subdirectory names within specified directory • File • Allow user to view file name for specified file F
Access Rights Security • Access Control Access Right • Directory • Allows users to grant access rights to other users for this directory • File • Allow user to grant access rights for specified file A
Directory Entry Table • Record of file name on volume • List of Trustees and Access Rights • 6 trustees per entry
Trustee • Directory Trustee • user, group, or container object that has been granted access rights to a directory • File Trustee • user or group that has been granted acces rights to a file
Effective Rights • The rights that ultimately control what functions a user can perform in a specified directory or file • Consist of one or more… • user trustee assignments • user’s group membership • container trustee assignments to user or group • Inherited rights through container, user, group • Inherited rights filter
Countries France Spain Home Volume Access Rights What are Bill’s Effective rights? Countries Spain France IRF [] Bill [RWCFM] IRF [] IRF []
Countries France Spain Home Volume Inherited Rights What are Bill’s Effective rights? Countries Spain France IRF [] Bill [RWCFM] IRF [] IRF [CM]
Home Volume Countries France Spain Access Rights What are Bill’s Effective rights? Countries Spain France IRF [CM] Bill [RWCFM] IRF [] Bill [RW] IRF [CRM]
Home Volume Countries France Spain Group Rights Accounting Bill IRF [] Bill [SRWCFM] IRF [CEM] Bill [RFM] IRF [] Accounting[REA]
Tools Use Windows Explorer tool to view and modify file system security settings.
Tools Use Windows Explorer tool to view and modify file system security settings.
Tools Use NWAdmin to add trustees and security settings to the file system.
Tools Use NWAdmin to add trustees and security settings to the file system.
Documenting Access Rights • RIGHTS
Documenting Access Rights • RIGHTS /S /T
Attribute Security • File Attributes • A, Cc, Ci, Di, Dc, Ds, X, H, Ic, M, P, Ro, Rw, Ri, Sh, Sy, T • Directory Attributes • Di, Dc, Dm, N, H, Ic, P, Ri, Sy
Tools Use Windows Explorer tool to view and modify file attribute settings.
Tools Use NWAdmin tool to view and modify file attribute settings.
NDS Security • Allows users to view, access, create, or modify NDS objects and their properties • NDS security and File System are similar and separate • Separate administrators for containers
Access Control List • List of users, groups or containers that have rights to the object – trustees • [Public] – all VLM client computers • [Root] – all users in NDS tree
Two Parts of NDS Security • Object Rights • what a trustee is allowed to do the object itself • Property Rights • What a trustee can do with the properties and their values within the object
Browse Right • Similar to the File Scan right in file system security. • Allows the trustee to see the object in the tree.
Create Right • When assigned to a container, the create right allows the trustee to create leaf and sub-container objects. • Cannot be assigned to leaf objects.
Rename, Delete and Supervisor • Rename and Delete rights allow the trustee to rename or delete the container or leaf object. • The Supervisor right provides all other rights including Supervisor rights to all properties.
Inheritable Right • New right with NetWare 5. • Granting a trustee the Inheritable right allows the trustee’s object rights given in the trustee assignment to be inherited by all leaf objects and subcontainers.
Read and Compare Rights • The Read right allows the trustee to view the contents of the property. • The Compare right is a subset of the Read right and only allows the trustee to compare a given value to the property without actually viewing the contents of the property.
Write and Add Self rights • The Write right allows a trustee to change the contents of a property. • The Add Self right is a special case of the Write right and allows a trustee to make themselves a member of the object, or remove themselves from the object. • Add self is usually only assigned to group type objects.
Inheritable Right • Allows the trustee’s assignment to be inherited by sub-containers and leaf objects. • Can be assigned to All properties or selected properties. • Assigning Inheritable to a selected property allows only that property to be inherited by sub-containers and leaf objects.
Effective Rights • What actions the trustee can perform as a result of one of more of the following: • Direct trustee assignment • Trustee assignment made to group or container • Trustee assignment made to parent container • Rights inherited from a parent container • Rights lost through a Inherited Rights Filter (IRF)
Tools of the Trade • NetWare Administrator Property Rights Object Rights
Effective Rights • NetWare Administrator Effective Rights
Note • Make sure that G: is mapped to UAS_HOST_CORP:##CORP