• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Another Windows/OI/Napp-It ACL question

JeKaRe

n00b
Joined
Sep 14, 2011
Messages
4
Hi All,

So after lots of reading i did it: i build my own All-in-One with Napp-It based on OI-dev-148.
The hardware part is working as expected and is a big improvement compared to my old Synology DS207. The software is giving me headaches at this point because i cannot get the rights and permissions as i intended.

Following the instructions for sharing in workgroup mode i can indeed share my ZFS folders with windows. If i look in the shared folder's properties i see a group Everyone and a user OPENINDIANA\Administrator and both have all rights. This goes for *every* shared folder.

There is no way i can assign other users or rights at this point. (or i must be doing something wrong)

I have been trying to accomplish this by using the new Napp-It extension ACL-Settings, but that results almost every time in an unaccessible share. (I must definetely be doing something wrong there...)

My goal is to give every group member their own shared folder which will not be accessible by the other members of the group and also have some folders that should be available to everyone. Well, a pretty standard setup i guess...

My ZFS Folders are set up as follows, using my family as an example, but in the end i will be using this datastore for three different groups of users.

Tank
Tank\family
Tank\family\father
Tank\family\mother
Tank\family\son1
Tank\family\son2
Tank\family\daughter
Tank\family\photo (shared among all family members)
Tank\family\video (shared among all family members)
Tank\family\music (shared among all family members)

I am using Windows 7 Ultimate, but because of the reported problems with that i also tried everything from a XP Pro virtual machine but with the same results. In fact i did not even see any differences in the way the ACL was handled by the two windows versions.

Surely there are others with a similar setup, please explain the setup details to me. I've read the fora and manuals dozens of times by now and i must be overlooking something or my interpretation of the instructions is somehow wrong....

If this setup is to be achieved by console commands instead of Windows GUI or Napp-It, i am eager to try. I'm no expert in *nix but i'm not afraid of it either...

With kind regards, Jack.
 
Hi All,

So after lots of reading i did it: i build my own All-in-One with Napp-It based on OI-dev-148.
The hardware part is working as expected and is a big improvement compared to my old Synology DS207. The software is giving me headaches at this point because i cannot get the rights and permissions as i intended.

Following the instructions for sharing in workgroup mode i can indeed share my ZFS folders with windows. If i look in the shared folder's properties i see a group Everyone and a user OPENINDIANA\Administrator and both have all rights. This goes for *every* shared folder.

There is no way i can assign other users or rights at this point. (or i must be doing something wrong)

I have been trying to accomplish this by using the new Napp-It extension ACL-Settings, but that results almost every time in an unaccessible share. (I must definetely be doing something wrong there...)

My goal is to give every group member their own shared folder which will not be accessible by the other members of the group and also have some folders that should be available to everyone. Well, a pretty standard setup i guess...

My ZFS Folders are set up as follows, using my family as an example, but in the end i will be using this datastore for three different groups of users.

Tank
Tank\family
Tank\family\father
Tank\family\mother
Tank\family\son1
Tank\family\son2
Tank\family\daughter
Tank\family\photo (shared among all family members)
Tank\family\video (shared among all family members)
Tank\family\music (shared among all family members)

I am using Windows 7 Ultimate, but because of the reported problems with that i also tried everything from a XP Pro virtual machine but with the same results. In fact i did not even see any differences in the way the ACL was handled by the two windows versions.

Surely there are others with a similar setup, please explain the setup details to me. I've read the fora and manuals dozens of times by now and i must be overlooking something or my interpretation of the instructions is somehow wrong....

If this setup is to be achieved by console commands instead of Windows GUI or Napp-It, i am eager to try. I'm no expert in *nix but i'm not afraid of it either...

With kind regards, Jack.

first check if there are any id-mappings between Windows (domain) and Unix
In workgroup mode, delete all id-mappings (see Menu services-smb-idmpping)

second, you need to create all users on OI

third you need to set ACL
You can allow everyone=modify on the common folders
and on the private folders you can delete all permissions but
the needed user=modify (plus root=full, but root can always access even with no ACL setting
because he is the owner and the owner can always modify permissions- you cannot outlock yourself)

alternatively you may assign ACL on groups, but you must know that ACL are related to Windows
compatible SMB groups. They are different from OI-unix groups. In napp-it user-management you can
create SMB groups and assigne members. From Windows you can use these groups.
Napp-it ACL extension is currently for user settings only - not SMB groups (on developmen,t
i currently lack some time to work on it)
 
Hi Gea,

1. I have only one usermapping which is winuser:Administrator@openindiana to unixuser:root. This mapping was created by the fact that i added one user to the administrators smb-group (as was mentioned in the manual)

2, Yes, i did create all users also on OI with the exact same username and password as they use in Windows.

3. I need to set ACL. This is probably the point where i am doing something wrong. Do i set the ACL in Napp-It? Only place i found where i can set the folder ACL is in the ZFS-Folder menu by clicking on the value in column FOLDER-ACL. Is that the correct place? I can set the rights there for current owner, current group and everyone, but not for a specific user. As you mentioned the root is always the owner, so how do i allow a specific user to modify?

My guess at this point would be to chown to my specific user (ie. chown Tank/family/father to father) and then set ACL current owner@ to modify_set. Is that the correct way?

Thank you for your reply...

Jack.
 
Hi Gea,

1. I have only one usermapping which is winuser:Administrator@openindiana to unixuser:root. This mapping was created by the fact that i added one user to the administrators smb-group (as was mentioned in the manual)

2, Yes, i did create all users also on OI with the exact same username and password as they use in Windows.

3. I need to set ACL. This is probably the point where i am doing something wrong. Do i set the ACL in Napp-It? Only place i found where i can set the folder ACL is in the ZFS-Folder menu by clicking on the value in column FOLDER-ACL. Is that the correct place? I can set the rights there for current owner, current group and everyone, but not for a specific user. As you mentioned the root is always the owner, so how do i allow a specific user to modify?

My guess at this point would be to chown to my specific user (ie. chown Tank/family/father to father) and then set ACL current owner@ to modify_set. Is that the correct way?

Thank you for your reply...

Jack.

1.
i would try without any mapping ion workgroup mode

3. you can set ACL from Windows when connected as root, via CLI
or via napp-it ACL extension (currently only user, not goups) with menu
extension- acl. With last option you can care about ACL order.

I would not change owner, just add modify or full permission for other users
 
Hi Gea,

1. Very well, i removed all user mappings

3. That's the point. In windows properties for a shared ZFS folder, in the Security tab, i only see group Everyone and user root (OPENINDIANA\root). If i try to add one of the other users which are created on both Windows and OI i get the 'Select Users or Groups' dialogue with the location openindiana prefilled and not changeable. If i enter a username i only get the message: An object named "username" cannot be found. So, how do i add another user...

I will try the ACL extension again tomorrow,..

Greetings, Jack.
 
So, i used in Napp-It extension -> ACL Settings to add my intended user (ie Father) to a ZFS Folder as rule #0. There already are rules for root (full rights) and everyone (read only). I gave Father full rights and restarted the smb service.

Then i went back to windows, logged in as Father and opened the shared folder.
At that point i need to provide credentials. If i use Father's credentials i cannot connect to the share. If i use the root's credentials the shared folder is opened and i can read and write to it, it seems all fine. In properties -> security i can see now that Father is added as a user with full rights. (I still cannot add users here)

Only problem is that Father can now connect to all other shared folders as well to read AND write to them and that is not acceptable.

Regards, Jack
 
So, i used in Napp-It extension -> ACL Settings to add my intended user (ie Father) to a ZFS Folder as rule #0. There already are rules for root (full rights) and everyone (read only). I gave Father full rights and restarted the smb service.

Then i went back to windows, logged in as Father and opened the shared folder.
At that point i need to provide credentials. If i use Father's credentials i cannot connect to the share. If i use the root's credentials the shared folder is opened and i can read and write to it, it seems all fine. In properties -> security i can see now that Father is added as a user with full rights. (I still cannot add users here)

Only problem is that Father can now connect to all other shared folders as well to read AND write to them and that is not acceptable.

Regards, Jack

i suppose, you have one ZFS-folder/ share with several simple subfolders.
In this case you need to set different ACL on these subfolders.

You can do this from some Windows versions as root or via CLI.
The ACL extension currently supports only ACL on a ZFS folder/ dataset
not on simple folders.

or
you can create different ZFS folders, one for each user
 
Back
Top