Casper> [[ PLEASE DON'T SEND ME EMAIL COPIES OF POSTINGS ]]
Quote:>> In our network we need detailed control to file access. The normal
>> unix file permissions don't give us enough controlability, so I use
>> ACLs. Now we want to mount such a filesystem on a Linux box using
>> NFS. I have done some tests but it doesn't work. It seems to me that
>> the ACLs are not checked over NFS.
Casper> Does this happen when you give more permission with ACL, less, or
Thank you for your informations, Casper.
I want to give more permission with ACL to the file. Below I show the
information about a test.
share -F nfs -o rw=<my-host> /var/log/acl-test
lucida:/var/log/acl-test:root ls -al
drwxrwxr-x+ 2 root other 512 Feb 28 11:10 ./
drwxr-xr-x 7 root sys 1024 Feb 28 11:43 ../
-rw-rw----+ 1 root root 12 Feb 28 11:22 test
lucida:/var/log/acl-test:root getfacl test
# file: test
# owner: root
# group: root
As user root:
lucida:/var/log/acl-test:root cat test
As user dirksen:
lucida:/var/log/acl-test:dirksen cat test
mount -t nfs -o vers=2 lucida:/var/log/acl-test /mnt/nfs
feynman:/mnt/nfs:dirksen cat test
cat: test: Permission denied
Casper> If the client performs the checks locally (wrong!) then you will only
Casper> get the standard permissions.
Casper> With NFSv3, client should call the NFS3_ACCESS function;
Casper> with NFSV2, there's really no way to do this without trying operations
Casper> over the wire (which isn't possible with, e.g., access(2))
Quote:>> Have anybody an idea what the problem may be? Does the NFS-client or
>> the the NFS-Server check the file permissions? If the server
>> checks the permissions then the linux client doesn't need to know
>> anything about the ACLs and it should work.
Casper> In principle it's the server that should be doing the checking;
Casper> the Linux NFS clietns may be doing checks of its own.
Casper> Expressed in this posting are my opinions. They are in no way related
Casper> to opinions held by my employer, Sun Microsystems.
Casper> Statements on Sun products included here are not gospel and may
Casper> be fiction rather than truth.
Dipl.-Inform. Uwe Dirksen
Lehrstuhl fuer Umformtechnik (LFU), Universit?t Dortmund
Baroper Str. 301, 44221 Dortmund
Tel: ++49 231 755-2605 Fax: ++49 231 755-2489