summaryrefslogtreecommitdiff
path: root/docs/docbook/smbdotconf/security/forcesecuritymode.xml
blob: 2db50f1ce3fca230b4b11b3d473a706aea3f43f6 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
<samba:parameter xmlns:samba="http://samba.org/common">
		<term><anchor id="FORCESECURITYMODE"/>force security mode (S)</term>
		<listitem><para>This parameter controls what UNIX permission 
		bits can be modified when a Windows NT client is manipulating 
		the UNIX permission on a file using the native NT security dialog 
		box.</para>
		
		<para>This parameter is applied as a mask (OR'ed with) to the 
		changed permission bits, thus forcing any bits in this mask that 
		the user may have modified to be on. Essentially, one bits in this 
		mask may be treated as a set of bits that, when modifying security 
		on a file, the user has always set to be 'on'.</para>

		<para>If not set explicitly this parameter is set to 0,
		and allows a user to modify all the user/group/world permissions on a file,
		with no restrictions.</para>
		
		<para><emphasis>Note</emphasis> that users who can access 
		the Samba server through other means can easily bypass this restriction, 
		so it is primarily useful for standalone &quot;appliance&quot; systems.  
		Administrators of most normal systems will probably want to leave
		this set to 0000.</para>

		<para>See also the <link linkend="FORCEDIRECTORYSECURITYMODE"><parameter moreinfo="none">
		force directory security mode</parameter></link>,
		<link linkend="DIRECTORYSECURITYMASK"><parameter moreinfo="none">directory security
		mask</parameter></link>, <link linkend="SECURITYMASK"><parameter moreinfo="none">
		security mask</parameter></link> parameters.</para>

		<para>Default: <command moreinfo="none">force security mode = 0</command></para>
		<para>Example: <command moreinfo="none">force security mode = 700</command></para>
		</listitem>
		</samba:parameter>