[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: /var/samba -> /var/state/samba script



On Tue, Jul 03, 2001 at 12:00:10PM +0200, Edward Betts wrote:
> alexander.skwar@delphiauto.com wrote:
> > 
> > On 30.06.2001 14:08:43 Edward Betts wrote:
> > 
> > > Depends, what are you sharing? Look at how ftp does it /home/ftp, I would
> > > recommend something similar.
> > 
> > Hmm, wouldn't /var/ftp be a better location for ~ftp?
> 
> Who do you recommend own the files that you are serving by anon ftp or samba?
> If you look at www the files are owned by the www-data user, so the most

they are not, and should not be.  

> sensible thing to do is to create a user and have them own the files, once you
> have created a user, they need a home directory, so you might as well store
> the files in /home.

this doesn't make sense for samba in general since users login under
thier account and files they upload are owned by them.  unless you
use an anoymous guest or something.  

if its all just read only access to everyone files can and probably
should just be owned by root, or whoever administers the export.  same
with /var/www, files there should not be owned by the web server since
all that accomplishes it allowing anyone managing to compromise the
web server in any way to deface your web site.

> I suppose one question is what you do with files that you want to share with
> different methods, if you want files to be accessible from http, ftp, samba
> and nfs what ownership do you use, and where do you put them?

depends what your doing with the export, for anonymous ftp its all
readonly so it should be owned by whoever maintains the ftp site, NOT
the user the ftpd runs as (duh), same with www.  samba too if its just
a readonly share for everyone.  if its for user storage why not just
export their ~/ ?

-- 
Ethan Benson
http://www.alaska.net/~erbenson/

Attachment: pgpYCzhW0yG24.pgp
Description: PGP signature


Reply to: