<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cifs share permissions not being enforced on unix volume in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Cifs-share-permissions-not-being-enforced-on-unix-volume/m-p/22182#M1963</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;For right now though when I create a cifs share of a unix qtree it isn't enforcing the share permissions at all.&lt;/PRE&gt;&lt;P&gt;Could you show output of "cifs shares &lt;EM&gt;share_name&lt;/EM&gt;" where &lt;EM&gt;share_name&lt;/EM&gt; is share for which permissions are not enforced? Is your system part of domain?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Sep 2011 06:47:46 GMT</pubDate>
    <dc:creator>aborzenkov</dc:creator>
    <dc:date>2011-09-13T06:47:46Z</dc:date>
    <item>
      <title>Cifs share permissions not being enforced on unix volume</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Cifs-share-permissions-not-being-enforced-on-unix-volume/m-p/22177#M1962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have some volumes that are unix primarily but still shared on cifs. The problem is the default nt user right now is root which I want to change but I have to fix a lot of volumes that were carried over first. For right now though when I create a cifs share of a unix qtree it isn't enforcing the share permissions at all. Any domain user can access the share and since they are root the unix permissions give them full access. Even enabling accessbasedenum doesn't help. So now viruses that write to open shares are hitting these and it's causing a large problem. If anyone knows what I can do with this please let me know. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:46:13 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Cifs-share-permissions-not-being-enforced-on-unix-volume/m-p/22177#M1962</guid>
      <dc:creator>mciardullo</dc:creator>
      <dc:date>2025-06-05T06:46:13Z</dc:date>
    </item>
    <item>
      <title>Cifs share permissions not being enforced on unix volume</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Cifs-share-permissions-not-being-enforced-on-unix-volume/m-p/22182#M1963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;For right now though when I create a cifs share of a unix qtree it isn't enforcing the share permissions at all.&lt;/PRE&gt;&lt;P&gt;Could you show output of "cifs shares &lt;EM&gt;share_name&lt;/EM&gt;" where &lt;EM&gt;share_name&lt;/EM&gt; is share for which permissions are not enforced? Is your system part of domain?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Sep 2011 06:47:46 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Cifs-share-permissions-not-being-enforced-on-unix-volume/m-p/22182#M1963</guid>
      <dc:creator>aborzenkov</dc:creator>
      <dc:date>2011-09-13T06:47:46Z</dc:date>
    </item>
    <item>
      <title>Cifs share permissions not being enforced on unix volume</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Cifs-share-permissions-not-being-enforced-on-unix-volume/m-p/22188#M1964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The output for one of the shares is here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;USILST76A&amp;gt; cifs shares ftp_ftpca&lt;/P&gt;&lt;P&gt;Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mount Point&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Description&lt;/P&gt;&lt;P&gt;----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -----------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -----------&lt;/P&gt;&lt;P&gt;ftp_ftpca&amp;nbsp;&amp;nbsp;&amp;nbsp; /vol/ftp_ftpca&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CA DLP Scanning share Mike Mendelsohn&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ... access based enum supported&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TANT-A01\dlpfsa / Read&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is happening to every share that is using a unix qtree and is being shared via cifs. It doesn't happen to mixed shares as it appears on mixed shares it enforces the share and ntfs permissions. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is on a domain. I thought it was something in usermap.cfg but after removing the line I thought was the problem it's still not enforcing the share permissions. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Sep 2011 11:45:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Cifs-share-permissions-not-being-enforced-on-unix-volume/m-p/22188#M1964</guid>
      <dc:creator>mciardullo</dc:creator>
      <dc:date>2011-09-13T11:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cifs share permissions not being enforced on unix volume</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Cifs-share-permissions-not-being-enforced-on-unix-volume/m-p/22192#M1965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I cannot reproduce it, at least in simple test. Running simulator in WORKGROUP mode and creating a share limited to specific group correctly denies access to a user not in this group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;simsim&amp;gt; qtree status&lt;/P&gt;&lt;P&gt;Volume   Tree     Style Oplocks  Status&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Sep 2011 12:37:02 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Cifs-share-permissions-not-being-enforced-on-unix-volume/m-p/22192#M1965</guid>
      <dc:creator>aborzenkov</dc:creator>
      <dc:date>2011-09-13T12:37:02Z</dc:date>
    </item>
    <item>
      <title>Cifs share permissions not being enforced on unix volume</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Cifs-share-permissions-not-being-enforced-on-unix-volume/m-p/22198#M1966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have also seen now if I create a cifs share and put a unix qtree under it that the share permissions are enforced at the top level but not on the qtree&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for example if I create a unix qtree under a share that is ntfs and that qtree is unix then a user can't open &lt;A target="_blank"&gt;\\share&lt;/A&gt;&lt;A&gt;&lt;/A&gt;&lt;A&gt;&lt;/A&gt; but can open &lt;A target="_blank"&gt;\\share\unixqtree&lt;/A&gt; even though there is no share for that spot specifically. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Sep 2011 16:35:49 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Cifs-share-permissions-not-being-enforced-on-unix-volume/m-p/22198#M1966</guid>
      <dc:creator>mciardullo</dc:creator>
      <dc:date>2011-09-13T16:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cifs share permissions not being enforced on unix volume</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Cifs-share-permissions-not-being-enforced-on-unix-volume/m-p/22203#M1967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You confuse share level and filesystem level permissions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be able to access &lt;BR /&gt;server\share\folder&amp;lt;file:///&lt;BR /&gt;server\share\folder&amp;gt; user must first have permissions to connect to &lt;BR /&gt;server\share&amp;lt;file:///&lt;BR /&gt;server\share&amp;gt;. If (s)he is not allowed to do it, there will be error right away and no way to access any file and/or folder inside this share at all. Your initial question was about share level access. And this is controlled by &lt;STRONG&gt;share&lt;/STRONG&gt; ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once user connects to share (assuming necessary permissions are granted) access to individual file(s) and/or folder(s) in this share is controlled by &lt;STRONG&gt;file&lt;/STRONG&gt; ACL. For Unix qtree these ACLs are reduced to standard Unix file owner, group and mode bits. For access check Windows user is mapped to Unix user and access is verified using standard Unix rules. If all your users are mapped to root, then every user has access to every file (on Unix qtree).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please read TR-3490 about multiprotocol access to NetApp.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Sep 2011 05:27:21 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Cifs-share-permissions-not-being-enforced-on-unix-volume/m-p/22203#M1967</guid>
      <dc:creator>aborzenkov</dc:creator>
      <dc:date>2011-09-14T05:27:21Z</dc:date>
    </item>
  </channel>
</rss>

