Re: Office 2008 Files: Read Only, POSIX, ACLs Frustration!



Decker 12 wrote:

I wish to lock down this folder, so I set POSIX permissions to Owner: Decker12, Read/Write, Group: Sales, Read/Write, Everyone: None.

This is what I do for my server permissions (recreating from memory at home):

Owner: <a local account on the server>
Group: <a local group on the server>
Everyone: None

ACLs:
Full Control: <same local account on the server>
Read/Write: <any group>
Read/Write: <any group>
Read only: <any group>
Read only: <any group>
Read only: Everyone from directory service, not local (if needed)

ACLs should always override standard permissions.

The reason I have this setup is because no network user or group with network users in it should *ever* have Full Control (Ownership) of any files or folders or permissions problems will be prevalent for non-owners.

How are your permissions set? To illustrate your setup you can take a screen shot and post it on <http://www.imageshack.us/> for free and without creating an account.


--

bill

Entourage Help Page <http://entourage.mvps.org/>
Entourage Help Blog <http://blog.entourage.mvps.org/>
YouTalk <http://nine.pairlist.net/mailman/listinfo/youtalk>
Twitter: follow <http://twitter.com/meck>
.



Relevant Pages

  • Re: Removing restricted access
    ... together when running on the same server. ... >>To allow Anonymous Access you have to check the ... >>Note that IIS will honor NTFS permissions. ... >>on domain or local account that has at least read ...
    (microsoft.public.inetserver.iis.security)
  • Shared Directories - Permissions
    ... write to certain folders as my own local account. ... W2K server via My Network Places (I mapped the server and ... the shared drive) I do not have the same permissions. ... Again its a W2K Server and a Windows XP desktop. ...
    (microsoft.public.win2000.security)
  • Re: saving XmlDocument using Windows Authentication
    ... the permissions are set to Everyone on both the share ... We're not using a single account for impersonation. ... >¤ We have a share on a server that we want the ... If it's a local account then ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: read priviliges for key for specific local account
    ... I would like to read the permissions for the below key. ... with all the server names that I would like to do this on. ... For example I would like to see what "Network Services" local account ...
    (microsoft.public.scripting.vbscript)
  • Re: write with cURL
    ... execute permissions. ... of potential security risks from other users on the same server. ... I made this suggestion because their web host appears to run Apache ... risk to allow Apache's group write access, since all PHP scripts ran ...
    (alt.php)