User Restrictions: Some Oes 2 Limitations - Novell OPEN ENTERPRISE SERVER 2 SP2 - PLANING AND IMPLEMENTATION GUIDE 11-10-2009 Implementation Manual

Planning and implementation guide
Table of Contents

Advertisement

Feature
POSIX / Linux
Subdirectory and file
Permissions granted to a file or directory
visibility
apply to only the file or directory. Users
can't see parent directories along the path
up to the root unless permissions are
granted (by setting the UID, GID, and mode
bits) for each parent.
After permissions are granted, users can
see the entire contents (subdirectories and
files) of each directory in the path.
When an NCP volume is created on a Linux POSIX or NSS volume, some of the behavior described
above is modified. For more information, see the
Guide, particularly the
"NCP on Linux

21.2.2 User Restrictions: Some OES 2 Limitations

Seasoned NetWare administrators are accustomed to being able to set the following access
restrictions on users:
Account balance restrictions
Address restrictions
Intruder lockout
Login restrictions
Password restrictions
Time restrictions
Many of the management interfaces that set these restrictions (iManager, for example), might seem
to imply that these restrictions apply to users who are accessing an OES 2 server through any
protocol.
This is generally true, with two important exceptions:
Maximum number of concurrent connections in login restrictions
Address restrictions
These two specific restrictions are enforced only for users who are accessing the server through
NCP. Connections through other access protocols (for example, HTTP or CIFS) have no concurrent
connection or address restrictions imposed.
For this reason, you probably want to consider not enabling services such as SSH and FTP for LUM
when setting up Linux User Management. For more information on SSH and LUM, see
Section 11.4, "SSH Services on OES 2," on page
For more information on Linux User Management, see
for eDirectory Users" on page
see
Table 15-2 on page
152.
OES 2 SP2: NCP Server for Linux Administration
Security" section.
93.
"Linux User Management: Access to Linux
149. For more information on the services that can be PAM-enabled,
Novell Trustee Model on OES 2
When users are given a trustee
assignment to a file or directory,
they can automatically see each
parent directory along the path up
to the root. However, users can't
see the contents of those
directories, just the path to where
they have rights.
Security 221

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the OPEN ENTERPRISE SERVER 2 SP2 - PLANING AND IMPLEMENTATION GUIDE 11-10-2009 and is the answer not in the manual?

Questions and answers

This manual is also suitable for:

Open enterprise server 2 sp2

Table of Contents