This is the old XigmaNAS forum in read only mode,
it will taken offline by the end of march 2021!



I like to aks Users and Admins to rewrite/take over important post from here into the new fresh main forum!
Its not possible for us to export from here and import it to the main forum!

No permission

CIFS/SMB network sharing.
Forum rules
Set-Up GuideFAQsForum Rules
Post Reply
himbrr
Advanced User
Advanced User
Posts: 153
Joined: 21 Oct 2012 21:16
Location: Germany
Status: Offline

No permission

Post by himbrr »

Hi,

as advised I followed the tutorial from alexey.
I've created 4 users and 2 groups (winshare, windnld).
My samba settings:
Image
Image

I have 3 shares. One for the users. They will have access to all folders, not only their home (group winshare).
The second is for the download folder, only users of group windnld will have read and write access.
Last but not least we have a third folder. This stores all the media files, such as movies, music, pictures.
Group winshare should have access.
Image

Here you see the settings of each share:
Image
Image
Image


With Winscp I have changed the group of each folder.
winshare = home and media folders
windnld = download folder
Permissons for folders are 0666.
I know I have to change it to 0660 for the download folder. Will do this at the end.

At the network are only windows 7 pcs/laptops, but I can't access from any of them to any folder.
I tried all users. No access.

What went wrong by configuring the shares?
Nas4Free 9.2.0.1.972, ASUS P8H77-I, 8GB RAM, Intel Celeron CPU G530 @ 2.40GHz, 5x 2TB WD Red, 1x 60GB OCZ Vertex 2

User avatar
alexey123
Moderator
Moderator
Posts: 1469
Joined: 19 Aug 2012 08:22
Location: Israel, Karmiel
Contact:
Status: Offline

Re: No permission

Post by alexey123 »

What went wrong by configuring the shares?

Read second, third and forth post on forum
You can begin from forth post.
The trick is that the samba share is only one, no more, but with a symbolic name and a symbolic path. Users do not even know how many folders I created - they see only his folder.
This building I made for give access to my share for 7 users over ftp, smb, and web.
All users, which have access, can read and write into share, use share as Windows folder (but not delete files in most folders inside public). User folders have exactly the same structure for all protocols - no matter how they connect it looks the same.
Folder always mounted on desktop, and sometimes I even forget that it is not placed on the computer.. :D
Home12.1.0.4 - Ingva (revision 7091)/ x64-embedded on AMD A8-7600 Radeon R7 A88XM-PLUS/ 16G RAM / UPS Ippon Back Power Pro 600
Lab 12.1.0.4 - Ingva (revision 7091) /x64-embedded on Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz / H61M-DS2 / 4G RAM / UPS Ippon Back Power Pro 600

himbrr
Advanced User
Advanced User
Posts: 153
Joined: 21 Oct 2012 21:16
Location: Germany
Status: Offline

Re: No permission

Post by himbrr »

No I don't want to have separated home directories.
All users have full access to the home dir.
In the home dir every user has a folder, but all users have access to all other folders.
I don't want to separate the access to only the users home.

The groups of the users:
user1= windnld,winshare
user2,user3,user4= winshare

Only user1 will have access to the download folder.
Nas4Free 9.2.0.1.972, ASUS P8H77-I, 8GB RAM, Intel Celeron CPU G530 @ 2.40GHz, 5x 2TB WD Red, 1x 60GB OCZ Vertex 2

User avatar
alexey123
Moderator
Moderator
Posts: 1469
Joined: 19 Aug 2012 08:22
Location: Israel, Karmiel
Contact:
Status: Offline

Re: No permission

Post by alexey123 »

In my case each user have full acces to each home folder.
But you need define groups equally, if user1 is member of windnld,winshare
user2,user3,user4= winshare need be members of windnld,winshare.
Another ---User 1 is not the same pack as the other, buiding not work.
Only user1 will have access to the download folder
What power does not give you the opportunity to place a folder inside your home directory for the user1 :o Are you root?
Home12.1.0.4 - Ingva (revision 7091)/ x64-embedded on AMD A8-7600 Radeon R7 A88XM-PLUS/ 16G RAM / UPS Ippon Back Power Pro 600
Lab 12.1.0.4 - Ingva (revision 7091) /x64-embedded on Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz / H61M-DS2 / 4G RAM / UPS Ippon Back Power Pro 600

himbrr
Advanced User
Advanced User
Posts: 153
Joined: 21 Oct 2012 21:16
Location: Germany
Status: Offline

Re: No permission

Post by himbrr »

I want to prohibit user2-4 to have access to the download folder.
alexey123 wrote:What power does not give you the opportunity to place a folder inside your home directory for the user1 :o Are you root?
user1 = admin and has access to use the shell.
But he is not root. He also have no admin access to the webinterface.
Just he should have the permission to browse, read and write the download folder.
Nas4Free 9.2.0.1.972, ASUS P8H77-I, 8GB RAM, Intel Celeron CPU G530 @ 2.40GHz, 5x 2TB WD Red, 1x 60GB OCZ Vertex 2

User avatar
alexey123
Moderator
Moderator
Posts: 1469
Joined: 19 Aug 2012 08:22
Location: Israel, Karmiel
Contact:
Status: Offline

Re: No permission

Post by alexey123 »

himbrr wrote:I want to prohibit user2-4 to have access to the download folder.
If folder downloads will placed inside home folder for user1, any user with nologin shell can not view this folder.
They will not even guess at the existence of a folder downloads



himbrr wrote:
alexey123 wrote:What power does not give you the opportunity to place a folder inside your home directory for the user1 :o Are you root?
user1 = admin and has access to use the shell.
Just he should have the permission to browse, read and write the download folder.
Aaaaaaaa I understand now. Your name is user1.
But he is not root. He also have no admin access to the webinterface.
Your have access to webgui, which work over php(always root) and not root? You can format storage and not root? Image
Home12.1.0.4 - Ingva (revision 7091)/ x64-embedded on AMD A8-7600 Radeon R7 A88XM-PLUS/ 16G RAM / UPS Ippon Back Power Pro 600
Lab 12.1.0.4 - Ingva (revision 7091) /x64-embedded on Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz / H61M-DS2 / 4G RAM / UPS Ippon Back Power Pro 600

himbrr
Advanced User
Advanced User
Posts: 153
Joined: 21 Oct 2012 21:16
Location: Germany
Status: Offline

Re: No permission

Post by himbrr »

With webguiI log in via "admin".
I changed the groups of the users.
The primary group of all users is winshare.
I've added all users to group ftp and user1 is as well in group windnld.

No user have access to shell. All users can login at the user portal.
Is my samba configuration correct?
Nas4Free 9.2.0.1.972, ASUS P8H77-I, 8GB RAM, Intel Celeron CPU G530 @ 2.40GHz, 5x 2TB WD Red, 1x 60GB OCZ Vertex 2

User avatar
alexey123
Moderator
Moderator
Posts: 1469
Joined: 19 Aug 2012 08:22
Location: Israel, Karmiel
Contact:
Status: Offline

Re: No permission

Post by alexey123 »

himbrr wrote:With webguiI log in via "admin".
I changed the groups of the users.
The primary group of all users is winshare.
I've added all users to group ftp and user1 is as well in group windnld.

No user have access to shell. All users can login at the user portal.
Is my samba configuration correct?
user1:windnld, ftp
user2:windnld, ftp
user3:windnld, ftp

better view when your users have some names

Code: Select all

nas folder  |  nas user  |   Win7 user
-----------------------------------------
user1           user1       user1 
user2           user2       user2 
user3           user3       user3 
Home12.1.0.4 - Ingva (revision 7091)/ x64-embedded on AMD A8-7600 Radeon R7 A88XM-PLUS/ 16G RAM / UPS Ippon Back Power Pro 600
Lab 12.1.0.4 - Ingva (revision 7091) /x64-embedded on Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz / H61M-DS2 / 4G RAM / UPS Ippon Back Power Pro 600

himbrr
Advanced User
Advanced User
Posts: 153
Joined: 21 Oct 2012 21:16
Location: Germany
Status: Offline

Re: No permission

Post by himbrr »

nas usernames and windows usernames are different.
nas folder | nas user | Win7 user
---------------------------------------------------------------------------------
/mnt/Management/Benuter/user1 user1 differentname1
/mnt/Management/Benuter/user2 user2 differentname1
/mnt/Management/Benuter/user3 user3 differentname1
/mnt/Management/Benuter/user4 user3 differentname1

When I try to connect via windows, I have to login.
I type "user1" and his password, but I have no access.
Image

users are in the requested groups.
Nas4Free 9.2.0.1.972, ASUS P8H77-I, 8GB RAM, Intel Celeron CPU G530 @ 2.40GHz, 5x 2TB WD Red, 1x 60GB OCZ Vertex 2

User avatar
alexey123
Moderator
Moderator
Posts: 1469
Joined: 19 Aug 2012 08:22
Location: Israel, Karmiel
Contact:
Status: Offline

Re: No permission

Post by alexey123 »

When I built it on Freenas7.2, I checked building with WinXP, Win98, ubuntu, Vista and Windows7. Now I not have Win7 and Vista, I kill Bill its :twisted: , sorry., I can'not test.
I have only 3*XP, Win98 and Ubuntu, and they works on NAS4Free Lab (my signature).
Test ftp access - work or not work.. If work, may be replace protocol - I connect over NT1. :?:
Home12.1.0.4 - Ingva (revision 7091)/ x64-embedded on AMD A8-7600 Radeon R7 A88XM-PLUS/ 16G RAM / UPS Ippon Back Power Pro 600
Lab 12.1.0.4 - Ingva (revision 7091) /x64-embedded on Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz / H61M-DS2 / 4G RAM / UPS Ippon Back Power Pro 600

himbrr
Advanced User
Advanced User
Posts: 153
Joined: 21 Oct 2012 21:16
Location: Germany
Status: Offline

Re: No permission

Post by himbrr »

FTP doesn't work. Only anonymous, but no user...
NT1 same... I change the owner of all folders back to root:wheel, like before.
Nas4Free 9.2.0.1.972, ASUS P8H77-I, 8GB RAM, Intel Celeron CPU G530 @ 2.40GHz, 5x 2TB WD Red, 1x 60GB OCZ Vertex 2

User avatar
alexey123
Moderator
Moderator
Posts: 1469
Joined: 19 Aug 2012 08:22
Location: Israel, Karmiel
Contact:
Status: Offline

Re: No permission

Post by alexey123 »

himbrr wrote:FTP doesn't work. Only anonymous, but no user...
If not working ftp, then what works? fan and power supply?
I do nothing with ftp server, only check Local users only, add maxlogin attempts to 5 and connections per ip to 10 and enable it.
Home12.1.0.4 - Ingva (revision 7091)/ x64-embedded on AMD A8-7600 Radeon R7 A88XM-PLUS/ 16G RAM / UPS Ippon Back Power Pro 600
Lab 12.1.0.4 - Ingva (revision 7091) /x64-embedded on Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz / H61M-DS2 / 4G RAM / UPS Ippon Back Power Pro 600

himbrr
Advanced User
Advanced User
Posts: 153
Joined: 21 Oct 2012 21:16
Location: Germany
Status: Offline

Re: No permission

Post by himbrr »

After resetting the folder permissions to root:wheel 777, I have anonymous access via SMB2.
Login via user didn't work :shock:
No authentication possible, all users have access to the download folder...

Now: when I log in via FTP I only can explore the users home dir. No other folders.. confusing...
alexey123 wrote: If not working ftp, then what works? fan and power supply?
That is a good question... pyLoad autostart? :D and MiniDLNA
Nas4Free 9.2.0.1.972, ASUS P8H77-I, 8GB RAM, Intel Celeron CPU G530 @ 2.40GHz, 5x 2TB WD Red, 1x 60GB OCZ Vertex 2

User avatar
lux
Advanced User
Advanced User
Posts: 193
Joined: 23 Jun 2012 11:37
Location: Bielefeld, Germany
Contact:
Status: Offline

Re: No permission

Post by lux »

@ himbrr

pls start from scatch with fresh N4f install! pyload & minidlna are not implemented 'out of the box'

so i assume you have decisively changed your System

start with fresh install and see how it works...! ;)
Home:11.3.x.7538/emb@32GB USB|1270v2@X9SCA-F|ECC32GB|i340-T4[lagg@GS108Tv2&smb-mch]|M1015@IT|9HDD~40TB@3xRaidZ1+1HDD+2SSD i335&i520+1xi800P@ZIL|~44W idle@SS-400FL2|Nanoxia Deep Silence 6B|24/7
Services: CIFS, FTP, TFTP, SSH, NFS, Rsync, Syncthing, Webserver, BitTorrent, VirtualBox | Extensions: OBI, TheBrig[certbot, Asterisk] | Extensions via vBox: Pi-hole, Jellyfin & zigbee2mqtt @DebianVM's
Test:12.x/emb@16GB USB|X3 420e@M4A88TD-V|16GB|i350-T2|M1015@IT|8xHDD+3xSSD[different Size&Brand]RaidZ1+2|for TESTing only

himbrr
Advanced User
Advanced User
Posts: 153
Joined: 21 Oct 2012 21:16
Location: Germany
Status: Offline

Re: No permission

Post by himbrr »

@lux
when i reinstall nas4free, what is with the data on my zfs raid?
Is this data safe on the disks??
Nas4Free 9.2.0.1.972, ASUS P8H77-I, 8GB RAM, Intel Celeron CPU G530 @ 2.40GHz, 5x 2TB WD Red, 1x 60GB OCZ Vertex 2

User avatar
lux
Advanced User
Advanced User
Posts: 193
Joined: 23 Jun 2012 11:37
Location: Bielefeld, Germany
Contact:
Status: Offline

Re: No permission

Post by lux »

YES, absolutely!!!

do NOT delete any Pools via WebIf!! - if then any ZFS Metadata on your Disc's are gone!!

just add your Disc's in Managment in fresh installed N4f with 'Preformatted Filesystem' -> 'ZFS Storage pool device'

after that go to 'Discs' - 'ZFS' - 'Configuration' - 'Synchronize' - hit the 'Synchronize' Button - et voilá your Pool is up'n runnng...

btw. do NOT restore your old Config - if any trouble in there you will import this on your fresh System!

if all Services up'n running ( smb, ftp... and you have tested & work o.k. ) then you can install all your own stuff like pyload / minidlna / etc...

greetings
Home:11.3.x.7538/emb@32GB USB|1270v2@X9SCA-F|ECC32GB|i340-T4[lagg@GS108Tv2&smb-mch]|M1015@IT|9HDD~40TB@3xRaidZ1+1HDD+2SSD i335&i520+1xi800P@ZIL|~44W idle@SS-400FL2|Nanoxia Deep Silence 6B|24/7
Services: CIFS, FTP, TFTP, SSH, NFS, Rsync, Syncthing, Webserver, BitTorrent, VirtualBox | Extensions: OBI, TheBrig[certbot, Asterisk] | Extensions via vBox: Pi-hole, Jellyfin & zigbee2mqtt @DebianVM's
Test:12.x/emb@16GB USB|X3 420e@M4A88TD-V|16GB|i350-T2|M1015@IT|8xHDD+3xSSD[different Size&Brand]RaidZ1+2|for TESTing only

User avatar
alexey123
Moderator
Moderator
Posts: 1469
Joined: 19 Aug 2012 08:22
Location: Israel, Karmiel
Contact:
Status: Offline

Re: No permission

Post by alexey123 »

Lux absolutely right!
himbrr, you need install fresh nas4free, and reconfigure it by hands.
Also for future experiments create VirtualBox mashine, which will copy of your server, exclude storage.
And important!
1. If you run full version - not install jail from wiki! This install work correctly with embedded instalation only
2. After 424 version, my google pages about php not valid! Also not valid any articles on internet about php on old Freenas or NAS4free, exclude daoyama blog about ounCloud, and VirtualBox + phpVirtualBox :roll: - need retest and rewrite all.
Home12.1.0.4 - Ingva (revision 7091)/ x64-embedded on AMD A8-7600 Radeon R7 A88XM-PLUS/ 16G RAM / UPS Ippon Back Power Pro 600
Lab 12.1.0.4 - Ingva (revision 7091) /x64-embedded on Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz / H61M-DS2 / 4G RAM / UPS Ippon Back Power Pro 600

himbrr
Advanced User
Advanced User
Posts: 153
Joined: 21 Oct 2012 21:16
Location: Germany
Status: Offline

Re: No permission

Post by himbrr »

alexey123 wrote:1. If you run full version - not install jail from wiki! This install work correctly with embedded instalation only
How to create a jail with the full version? O.o
My jail-data is saved on the ZFS pool. I just would mount this to /jail and create the startup scripts.. so I haven't to reinstall the whole jail...
The jail is already working fine ;)
alexey123 wrote:2. After 424 version, my google pages about php not valid! Also not valid any articles on internet about php on old Freenas or NAS4free, exclude daoyama blog about ounCloud, and VirtualBox + phpVirtualBox - need retest and rewrite all.
I don't need VMs on my NAS. Just an comfortable UPNP Client with transcoding, MySQL, PHP, pyLoad, SSH and the Samba shares. Most of them are built in ;)
Nas4Free 9.2.0.1.972, ASUS P8H77-I, 8GB RAM, Intel Celeron CPU G530 @ 2.40GHz, 5x 2TB WD Red, 1x 60GB OCZ Vertex 2

himbrr
Advanced User
Advanced User
Posts: 153
Joined: 21 Oct 2012 21:16
Location: Germany
Status: Offline

Re: No permission

Post by himbrr »

I started from scratch.
Windows shares are now working with authentication, but how to allow only one user to have access to the download folder?
Nas4Free 9.2.0.1.972, ASUS P8H77-I, 8GB RAM, Intel Celeron CPU G530 @ 2.40GHz, 5x 2TB WD Red, 1x 60GB OCZ Vertex 2

User avatar
alexey123
Moderator
Moderator
Posts: 1469
Joined: 19 Aug 2012 08:22
Location: Israel, Karmiel
Contact:
Status: Offline

Re: No permission

Post by alexey123 »

Code: Select all

mkdir <path_to_users>/user1/download
Only user1 have access to his download folder.
Home12.1.0.4 - Ingva (revision 7091)/ x64-embedded on AMD A8-7600 Radeon R7 A88XM-PLUS/ 16G RAM / UPS Ippon Back Power Pro 600
Lab 12.1.0.4 - Ingva (revision 7091) /x64-embedded on Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz / H61M-DS2 / 4G RAM / UPS Ippon Back Power Pro 600

himbrr
Advanced User
Advanced User
Posts: 153
Joined: 21 Oct 2012 21:16
Location: Germany
Status: Offline

Re: No permission

Post by himbrr »

This wont work...
Because all users have access to all shares.
e.g.
User1-4 have access to /mnt/data/homes/
/mnt/data/homes/ contain all shares for the users.
/mnt/data/homes/user1/
/mnt/data/homes/user2/
/mnt/data/homes/user3/
/mnt/data/homes/user4/

In this case user3 have access to /mnt/data/homes/user1/, /mnt/data/homes/user2/, etc
When I create a link to the download folder in user1 home, all users have access to this.
Current solution is only to mount the home and media folders on user2-3 pcs.
On user1 pc are all three folders mounted.
Nas4Free 9.2.0.1.972, ASUS P8H77-I, 8GB RAM, Intel Celeron CPU G530 @ 2.40GHz, 5x 2TB WD Red, 1x 60GB OCZ Vertex 2

User avatar
alexey123
Moderator
Moderator
Posts: 1469
Joined: 19 Aug 2012 08:22
Location: Israel, Karmiel
Contact:
Status: Offline

Re: No permission

Post by alexey123 »

himbrr wrote: User1-4 have access to /mnt/data/homes/
WHY?
I was say about buiding
user1 ----> home for it /mnt/data/homes/user1/
user2 -----> home for it /mnt/data/homes/user2/
etc
Home12.1.0.4 - Ingva (revision 7091)/ x64-embedded on AMD A8-7600 Radeon R7 A88XM-PLUS/ 16G RAM / UPS Ippon Back Power Pro 600
Lab 12.1.0.4 - Ingva (revision 7091) /x64-embedded on Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz / H61M-DS2 / 4G RAM / UPS Ippon Back Power Pro 600

himbrr
Advanced User
Advanced User
Posts: 153
Joined: 21 Oct 2012 21:16
Location: Germany
Status: Offline

Re: No permission

Post by himbrr »

No I said that the homes are not separated.
Just for home use, no separation needed.
Only the access for the download folder should be prohibited for the other users.
Nas4Free 9.2.0.1.972, ASUS P8H77-I, 8GB RAM, Intel Celeron CPU G530 @ 2.40GHz, 5x 2TB WD Red, 1x 60GB OCZ Vertex 2

User avatar
alexey123
Moderator
Moderator
Posts: 1469
Joined: 19 Aug 2012 08:22
Location: Israel, Karmiel
Contact:
Status: Offline

Re: No permission

Post by alexey123 »

Hmmmm.
What power against you use foldername homes instead public on my picture?
Image
Home12.1.0.4 - Ingva (revision 7091)/ x64-embedded on AMD A8-7600 Radeon R7 A88XM-PLUS/ 16G RAM / UPS Ippon Back Power Pro 600
Lab 12.1.0.4 - Ingva (revision 7091) /x64-embedded on Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz / H61M-DS2 / 4G RAM / UPS Ippon Back Power Pro 600

himbrr
Advanced User
Advanced User
Posts: 153
Joined: 21 Oct 2012 21:16
Location: Germany
Status: Offline

Re: No permission

Post by himbrr »

alexey123 wrote:What power against you use foldername homes instead public on my picture?
Yes this was the only solution.
I thought, samba can separate shares with different permissions.

Thank you for your help alexey123!
Nas4Free 9.2.0.1.972, ASUS P8H77-I, 8GB RAM, Intel Celeron CPU G530 @ 2.40GHz, 5x 2TB WD Red, 1x 60GB OCZ Vertex 2

Post Reply

Return to “CIFS/SMB (Samba)”