summaryrefslogtreecommitdiff
path: root/docs/docbook/smbdotconf/security/rootdirectory.xml
diff options
context:
space:
mode:
authorGerald Carter <jerry@samba.org>2003-10-10 16:46:22 +0000
committerGerald Carter <jerry@samba.org>2003-10-10 16:46:22 +0000
commitfec4b31bc1a76e408732e1a80b366d97fcf38143 (patch)
treee23398c2bcc4e3b2da28c8007ca453228aefb44f /docs/docbook/smbdotconf/security/rootdirectory.xml
parent20c7b998a38424e8e7b4d218f923937b9e8862d4 (diff)
downloadsamba-fec4b31bc1a76e408732e1a80b366d97fcf38143.tar.gz
samba-fec4b31bc1a76e408732e1a80b366d97fcf38143.tar.bz2
samba-fec4b31bc1a76e408732e1a80b366d97fcf38143.zip
removing docs tree from 3.0
(This used to be commit 0a3eb5574c91685ab07436c67b031266fb329693)
Diffstat (limited to 'docs/docbook/smbdotconf/security/rootdirectory.xml')
-rw-r--r--docs/docbook/smbdotconf/security/rootdirectory.xml34
1 files changed, 0 insertions, 34 deletions
diff --git a/docs/docbook/smbdotconf/security/rootdirectory.xml b/docs/docbook/smbdotconf/security/rootdirectory.xml
deleted file mode 100644
index 9c3e9cfad2..0000000000
--- a/docs/docbook/smbdotconf/security/rootdirectory.xml
+++ /dev/null
@@ -1,34 +0,0 @@
-<samba:parameter name="root directory"
- context="G"
- advanced="1" developer="1"
- xmlns:samba="http://samba.org/common">
-<listitem>
- <para>The server will <command moreinfo="none">chroot()</command> (i.e.
- Change its root directory) to this directory on startup. This is
- not strictly necessary for secure operation. Even without it the
- server will deny access to files not in one of the service entries.
- It may also check for, and deny access to, soft links to other
- parts of the filesystem, or attempts to use &quot;..&quot; in file names
- to access other directories (depending on the setting of the <link linkend="WIDELINKS">
- <parameter moreinfo="none">wide links</parameter></link>
- parameter).
- </para>
-
- <para>Adding a <parameter moreinfo="none">root directory</parameter> entry other
- than &quot;/&quot; adds an extra level of security, but at a price. It
- absolutely ensures that no access is given to files not in the
- sub-tree specified in the <parameter moreinfo="none">root directory</parameter>
- option, <emphasis>including</emphasis> some files needed for
- complete operation of the server. To maintain full operability
- of the server you will need to mirror some system files
- into the <parameter moreinfo="none">root directory</parameter> tree. In particular
- you will need to mirror <filename moreinfo="none">/etc/passwd</filename> (or a
- subset of it), and any binaries or configuration files needed for
- printing (if required). The set of files that must be mirrored is
- operating system dependent.</para>
-
- <para>Default: <command moreinfo="none">root directory = /</command></para>
-
- <para>Example: <command moreinfo="none">root directory = /homes/smb</command></para>
-</listitem>
-</samba:parameter>