Apple Mac OS X Server Print Service Administration For Version 10.4 or Later Instrukcja Użytkownika Strona 70

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 232
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 69
70 Chapter 4 Setting Up User Accounts
Avoiding Duplicate Short Names
Since short names are used to find user IDs of group members, duplicate short names
can result in file access being granted to groups you hadn’t intended to give access.
Return to the example of Tony and Tom Smith, who have duplicate short names.
Assume that the administrator has created a group in the root domain to which all
students belong. The group—AllStudents—has a GID of 2017.
Now suppose that a file, MyDoc, resides on a computer accessible to both Tony and
Tom. The file is owned by a user with the user ID 127. It has read-only access
permissions for AllStudents. Tony, not Tom, was added as a member of AllStudents, but
because a groups member list consists of short names, not user IDs, and the short
name tsmith is listed as a member of AllStudents, both Tony and Tom are effectively
members of AllStudents.
When Tom attempts to access MyDoc, Mac OS X determines that the owner
permissions do not apply for Tom, and moves on to check if group permissions apply
for Tom. Mac OS X searches the login hierarchy for user records with short names that
match those associated with AllStudents. Tom’s user record is found (short name
tsmith) because it resides in the login hierarchy, and the user ID in the user record is
compared with Toms login user ID. They match, so Tom is allowed to read MyDoc, even
though he’s not actually a member of AllStudents.
/
Students Faculty
T
ony’s computer
Tony Smith
(tsmith,smitty,
UID 3000)
Tom Smith (tsmith,smitty, UID 2000)
AllStudents (tsmith, GID 2017)
Tom’s computer
MyDoc
Owner 127 can: Read & Write
Group 2017 can: Read only
Everyone else can: None
Przeglądanie stron 69
1 2 ... 65 66 67 68 69 70 71 72 73 74 75 ... 231 232

Komentarze do niniejszej Instrukcji

Brak uwag