• Aucun résultat trouvé

Changing Disk Permissions

To change the permissions for a disk resource, follow these steps:

1. Select the Accounts menu and choose the File permissions menu item.

The File Access Permissions For dialog box appears.

2. Use the list box and Dir command button to move through the directories to find the resource server.

You can also type the pathname of the resource in the Filename text box.

The Edit File Permission dialog box appears.

4. Select the Set explicit permissions option button.

• If you want to use default permissions, see the "Assigning Default and Inherited Pennissions" section immediately following this one.

• If you want to remove the current permissions and start from scratch, choose the Clear permissions command button.

5 . Mark or unmark the following check boxes as needed:

• Audit this resource-If you want to keep track of who uses this resource, when, and what they do with it, you should mark this check box. See Chapter 12: Monitoring and Troubleshooting Server Operations, for details on resource auditing.

• Copy permissions to descendants-If you want to assign the permission for this resource to every directory and file below it in the directory structure, you should mark this check box. See the "Assigning Default and Inherited Permissions" section immediately following this one for details on inherited permissions.

6. Use the two list boxes, the Permission option buttons, and the Move command button to specify the permissions for each user and group as follows:

• To add a user or group to the Permitted list box, select that username or group name from the Not permitted list box and choose the Move

command button. The user or group moves to the Permitted list box with whatever permissions are currently selected among the permission option buttons. Each resource can have up to 64 entries in the Permitted list box.

• To remove a user or group from the Permitted list box, select that username or group name and choose the Move command button.

Managing User-Level Security

8

8-43

• To change the permissions for a user or group in the Permitted list box, choose that user name or group name and select one of the permission option buttons. If you select the Other option button, you can type a set of permissions in the text box below the option button.

See the "User-level Security" section earlier in this chapter for detailed descriptions of each permission option button.

7. Choose the OK command button.

Example

Mary Sullivan wants to share the c:\accounts directory on the mis server with the accounting group. She wants the group's members to be able to read or write to existing files in the directory.

In the LAN Manager screen, Mary selects the Accounts menu and chooses the File permissions menu item. In the File Access Permissions For dialog box, she selects [C:] in the Tree: list box and chooses the Dir command button. This displays the contents of drive C in the list box.

Mary selects the accounts directory in the list box and chooses the Zoom command button. In the Edit File Permission dialog box, she selects the RW option button, then moves the accounting group from the Not permitted list box to the Permitted list box. Mary finishes by choosing the OK command button. Having changed the permissions on the c:\accounts directory, she is now ready to share it.

on the network. The following sections explain the different options in detail.

NET ACCESS ~---~r---...,.~---:,...--t

Using NET ACCESS to Change Resource Permissions

To change the permissions for a spooled printer, disk, communication queues and IPC resources, use the NET ACCESS command with the following options:

net access resource [/addl/grantl/change]

account:permissions

resource is the full pathname of the drive, directory, or fue.

/add is the option that tells LAN Manager to add this resource to the access control database; use this if this is the first time you are assigning permissions for this resource.

/grarit is the option that tells LAN Manager to add permissions for a user or group to the access control database; use this if you are adding to the list of users or groups that have permission to use the resource.

/change is the option that tells LAN Manager to modify the existing permissions for a user or group.

Managing User-Level

8

Security

8-45

account is the user name or group name whose pennissions you want to change.

permissions is the permissions that you want to assign.

NOTE: For instructions on how to use the command flow diagram chart refer to Appendix C.

Using NET ACCESS to Remove User Permissions

To remove permissions for a user or group, use the NET ACCESS command with the following options:

net access resource /revoke account:

resource is the full pathname of the drive, directory, or flie.

/revoke is the option that tells LAN Manager to revoke permissions.

account is the user name or group name whose permissions you want to remove.

Using NET ACCESS to Remove Resource Permissions

To remove all permissions for a resource, use the NET ACCESS command with the following options:

net acce s s resource / de 1 e t e

resource is the full pathname of the drive, directory, or file.

/delete is the option that tells LAN Manager to remove this resource from the access control database.

following options:

net access resource / t r a i l : y

resource is the full pathname of the drive, directory, or flie.

trail:y is the option that tells LAN Manager to enable audit trailing.

Documents relatifs