LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-06-2009, 12:29 PM   #1
Deviathan
Member
 
Registered: Dec 2005
Posts: 52

Rep: Reputation: 18
samba security/winbind/ windows groups


Hi guys,
I thought this might be the appropriate forum to post in regarding an issue at my new job.

I was recently hired as a linux systems analyst at a state agency. This agency's datacenter is contracted out to a separate company so that they do all of the administrative work on the systems, which leaves me without any kind of admin access to the boxes.

Anyways, this agency has a development web server with tons of projects files and folders. This server also uses winbind for authentication and shares these files and folders through samba.

My issue is that I think files and folders should be owned by the people or groups working on them and not a service account with perms set to 777. Now, the samba side of things is locked down to a degree with access rights and such given to specific groups. That still doesn't account for the linux side of things.

Apparently multiple groups need to access these folders which kinda complicates things. I was thinking we could create groups that consist of those groups and then assign group ownership to that group. I've never tried creating groups of groups on the linux side and being that we're authenticating to windows AD, I'm not sure if putting windows groups in /etc/group would work ( probably not but I don't have the ability to experiment to be sure ).

My biggest complaint is seeing everything opened up (777) across the board.

What do you guys think?
 
Old 08-07-2009, 06:17 AM   #2
vishesh
Member
 
Registered: Feb 2008
Distribution: Fedora,RHEL,Ubuntu
Posts: 661

Rep: Reputation: 66
Dear
using winbind windows ad groups can be managed by linux for file/directory permission. what i mean is that create groups on AD and assign permission to that groups for file/directory on linux using chmod command. ACL can also be applied of linux in you want manage your permission from windows ad server.

Thanks

www.sambaguru.blogspot.com
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Active Directory groups via Samba/Winbind? dsdonut Linux - Newbie 3 01-23-2009 03:26 PM
Problem with Winbind mapping GID to Windows groups Thakowbbery Linux - Networking 0 08-29-2005 10:19 AM
winbind: wbinfo -g only lists global groups from PDC and not local groups saradiya Linux - Networking 0 12-01-2003 02:58 AM
SAMBA access based on NT Domain groups [using winbind] tisource Linux - Networking 1 11-24-2003 12:34 AM
Samba/Windows winbind questions pyrodex Linux - Software 1 05-30-2003 07:09 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:45 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration