LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 04-21-2006, 09:33 AM   #1
MitchM99
Member
 
Registered: Jan 2003
Distribution: Gentoo(Server) Ubuntu(desktop/laptop)
Posts: 63

Rep: Reputation: 15
Question Intergrating SAMBA share (w2k AD auth) and vsftp accounts


Hello,

First, thanks for taking the time to read this. I will try to provide as much detail as I can with out writing a book.

My current setup. Running SAMBA 3 with vsftpd on Ubuntu 5.10 SERVER. I installed krb5-user, winbind and SAMBA for w2k AD integration. I setup the share drive group to be a SECURITY group from AD so my folder permissions are as follows, (user(?)/group(AD Group)/other) This locks down the share folder so only the people in that SECURITY group can see the share. Work great. The current folder setup is like this

WebShare/
(several sub folders)/
Inbound/ and Outbound/
files below here

There will be several sub folders and each one will have an inbound and an outbound.

On top of this that want to have a client from a bunch of offsite locations to be able to upload and download files from the FTP server, with strict requirements of security on each subfolder from the root WebShare folder.

My issue here is I have no way to regulate folder/file permissions that the company puts into the SAMBA share folder(or at least that I am aware of) so for example, /WebShare/subfolderA/Inbound/ will need read write FTP access. No issue, I set the user to the FTP user set it 670 (group needs full access and is the SECURITY GROUP) but my issue is the /WebShare/subfolderA/Outbound foler. This one will be set for read only. so I set the "create mask = 470" in my smb.conf as this will be the only place files should be written to on the share drive side of the house. Here is my caveat, when they create a folder/file in Outbound the user gets set to the AD user that added it thus kicking out my FTP user's ability to see the folder/file. I could run a CRON to constantly change this process but that's not the best practice.

I'm not 100% sure if the office SAMBA users can set the user on the folders from within windows or not (I did install ACL's ont hat share drive) so this is the place where I am stuck. What are my options from here and how should I finish this up. I do have alternate means (ability to create a website for the upload process) and I currently have apache displaying the folders/files just fine on the web.

Can SAMBA and FTP work together like this or are they SOL on this type integration. Can I set multiple different permission schemes on those folder/files?

Thanks for the help

Mitch
 
Old 04-21-2006, 09:43 AM   #2
tomdkat
Member
 
Registered: May 2003
Location: S.F. Bay Area
Distribution: Ubuntu 9.04 AMD64
Posts: 595

Rep: Reputation: 30
I would take a look at vsftpd's config file and see if you can do any permissions magic through vsftpd. Also, read the vsftpd to see if there are additional directives you can specify to have permissions in vsftpd behave more like the Samba permissions you have setup.

One question, when someone greats a file/folder in "Outbound", how would they create it? Would they upload something via FTP or would "Outbound" be mapped as a Windows drive or something?

Peace...
 
Old 04-21-2006, 12:47 PM   #3
MitchM99
Member
 
Registered: Jan 2003
Distribution: Gentoo(Server) Ubuntu(desktop/laptop)
Posts: 63

Original Poster
Rep: Reputation: 15
Thanks for the response, all files/folders in Outbound are created by the SAMBA users via a Mapped windows drive.

Thanks
 
Old 04-21-2006, 01:38 PM   #4
tomdkat
Member
 
Registered: May 2003
Location: S.F. Bay Area
Distribution: Ubuntu 9.04 AMD64
Posts: 595

Rep: Reputation: 30
Ok, I think I understand your problem better. Let's confirm this.

A FTP user uploads a file to "Incoming" and on the Linux side the file looks like this:

-rw-rwx--- ftpuser security size date myfile.txt

Then someone puts a copy of myfile.txt in "Outgoing" and on the Linux side the file looks like this:

-r--rwx--- ADuser security size date myfile.txt

If that's right (or close), if the FTP user account is the same, you can maybe have Samba setup to make the ftpuser id the owner for files stored in Outgoing. I've never configured Samba with AD before but see if the "username map" function described in the smb.conf man page might help.

Peace...
 
Old 04-22-2006, 08:37 AM   #5
MitchM99
Member
 
Registered: Jan 2003
Distribution: Gentoo(Server) Ubuntu(desktop/laptop)
Posts: 63

Original Poster
Rep: Reputation: 15
I will look more into that, Thanks!
 
Old 04-24-2006, 01:28 PM   #6
tomdkat
Member
 
Registered: May 2003
Location: S.F. Bay Area
Distribution: Ubuntu 9.04 AMD64
Posts: 595

Rep: Reputation: 30
Quote:
Originally Posted by MitchM99
I will look more into that, Thanks!
Is my understanding of your problem correct? Let me know if the username map works.

Peace...
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
W2K cannot view samba share but can view NT FiveFlat Linux - Software 3 06-10-2005 02:54 PM
can't access samba share from w2k cliffyman Linux - Software 1 12-10-2003 12:31 PM
SAMBA bet RH 9 & W2K with Netgear Router - can't see W2K share cevjr Linux - Software 0 07-30-2003 11:44 AM
root access from W2K to SAMBA share slintz Linux - Software 1 06-03-2003 02:00 AM
howto? samba share NTFS mount to W2K client slintz Linux - Software 0 06-02-2003 06:43 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 09:52 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration