NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
chopin70
Nov 12, 2020Virtuoso
Shares user and and group permissions
Hi, 4 years after this thread... https://community.netgear.com/t5/Using-your-ReadyNAS-in-Business/User-and-group-broken-permissions/td-p/1107451/page/3 I am migrating to FreeNAS and turni...
StephenB
Nov 14, 2020Guru - Experienced User
Sandshark wrote:
chopin70 wrote:
nteresting
However, that is really a very bad fix you suggested
I agree. That is a good way for a home network, where SMB is typically the only protocol in use, so the admin doesn't get lost in the sea of both network and file permissions, but it is not suitable for a business environment.
I do agree that using Network Access alone doesn't work if you give a user with restricted access to files the ability to log into the NAS with SSH. But in my opinion that is bad practice anyway - only admins should have SSH access to the NAS.
I don't see what the other protocols have to do with it, since you need to set up network access for all of them properly anyway. If you try to use file permissions alone, then anyone with write access to the folder can change the permissions - so they can elevate the permissions of others. One way or another you need to set the network access for all protocols properly if you want to ensure that the restricted access sticks. And in most cases (home or business) that is enough.
chopin70
Nov 15, 2020Virtuoso
It doesn't work that way.
We should be able to set group ACLS from windows once the group permissions are specified in GUI. Currently even this basic acls part is broke.
Once ACLS permissions are set at group level, they would properly apply tu users and they will manage both smb AND unix accesses.
I have a sync_agent user to sync mobile phones to nas and an rsync user to accept pull requests for backups through ssh and not the insecure modules. So it needs a shell access with ssh cert and no pass. I also have a few users needing a shell access.
I properly secured a non root ssh access for the rsync user using sudo and a locked authorized_keys command pointing to a shell script.
In anycase, the way acls are implemented is buggy. And the way you suggest leaves a hole if a user needs shell access. The NAS is not sold as "Home only", so no excuses to leave it unfinished by Netgear. Hope it gets fixed.
Any Netgear tech we can ping ?
We should be able to set group ACLS from windows once the group permissions are specified in GUI. Currently even this basic acls part is broke.
Once ACLS permissions are set at group level, they would properly apply tu users and they will manage both smb AND unix accesses.
I have a sync_agent user to sync mobile phones to nas and an rsync user to accept pull requests for backups through ssh and not the insecure modules. So it needs a shell access with ssh cert and no pass. I also have a few users needing a shell access.
I properly secured a non root ssh access for the rsync user using sudo and a locked authorized_keys command pointing to a shell script.
In anycase, the way acls are implemented is buggy. And the way you suggest leaves a hole if a user needs shell access. The NAS is not sold as "Home only", so no excuses to leave it unfinished by Netgear. Hope it gets fixed.
Any Netgear tech we can ping ?
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!