diff options
author | cvs2svn Import User <samba-bugs@samba.org> | 2003-04-07 15:02:52 +0000 |
---|---|---|
committer | cvs2svn Import User <samba-bugs@samba.org> | 2003-04-07 15:02:52 +0000 |
commit | 951aec08e8480690acbb10ab5e7db78db2e72061 (patch) | |
tree | 099a6b97031961b9479924879735e8a0cd6bbeb0 /docs/docbook/smbdotconf/security/securitymask.xml | |
parent | a48d89bb9d0092d9b2368d55fdd1e2350210c012 (diff) | |
parent | f157e663f131bc26f351475226cce38b957cd0bd (diff) | |
download | samba-951aec08e8480690acbb10ab5e7db78db2e72061.tar.gz samba-951aec08e8480690acbb10ab5e7db78db2e72061.tar.bz2 samba-951aec08e8480690acbb10ab5e7db78db2e72061.zip |
This commit was manufactured by cvs2svn to create branch 'SAMBA_3_0'.(This used to be commit 43f21c87e12fe88dab6ccba13c2e54161cf87093)
Diffstat (limited to 'docs/docbook/smbdotconf/security/securitymask.xml')
-rw-r--r-- | docs/docbook/smbdotconf/security/securitymask.xml | 36 |
1 files changed, 36 insertions, 0 deletions
diff --git a/docs/docbook/smbdotconf/security/securitymask.xml b/docs/docbook/smbdotconf/security/securitymask.xml new file mode 100644 index 0000000000..ee3e8f916c --- /dev/null +++ b/docs/docbook/smbdotconf/security/securitymask.xml @@ -0,0 +1,36 @@ +<samba:parameter name="security mask" + context="S" + xmlns:samba="http://samba.org/common"> +<listitem> + <para>This parameter controls what UNIX permission + bits can be modified when a Windows NT client is manipulating + the UNIX permission on a file using the native NT security + dialog box.</para> + + <para>This parameter is applied as a mask (AND'ed with) to + the changed permission bits, thus preventing any bits not in + this mask from being modified. Essentially, zero bits in this + mask may be treated as a set of bits the user is not allowed + to change.</para> + + <para>If not set explicitly this parameter is 0777, allowing + a user to modify all the user/group/world permissions on a file. + </para> + + <para><emphasis>Note</emphasis> that users who can access the + Samba server through other means can easily bypass this + restriction, so it is primarily useful for standalone + "appliance" systems. Administrators of most normal systems will + probably want to leave it set to <constant>0777</constant>.</para> + + <para>See also the <link linkend="FORCEDIRECTORYSECURITYMODE"> + <parameter moreinfo="none">force directory security mode</parameter></link>, + <link linkend="DIRECTORYSECURITYMASK"><parameter moreinfo="none">directory + security mask</parameter></link>, <link linkend="FORCESECURITYMODE"> + <parameter moreinfo="none">force security mode</parameter></link> parameters.</para> + + <para>Default: <command moreinfo="none">security mask = 0777</command></para> + + <para>Example: <command moreinfo="none">security mask = 0770</command></para> +</listitem> +</samba:parameter> |