Page 1 of 1 1
Topic Options
#194640 - 2009-07-09 08:39 PM Create and Map Hidden Shares
MadMills Offline
Just in Town

Registered: 2009-05-20
Posts: 2
Loc: Los Angeles, CA
Hi there -
This should be a pretty simple one \:\)

I have a Server - let's say \\ServerName\Users\

I want to know if it is possible for Kixtart to:

Check for the existence of a User Share underneath the Users Folder -

Create Hidden Shares on the Server for that user using the @HOMESHR (or any other) variable should there be no Homeshare Folder -

Also - Is there any way to assign permissions to these folders using Kixtart without having to manually touch all of these folders?

Any assistance is appreciated. I am pretty green to Kixtart and apologize in advance if this is Kix 101.

Thanks

Top
#194651 - 2009-07-10 05:14 AM Re: Create and Map Hidden Shares [Re: MadMills]
Allen Administrator Online   shocked
KiX Supporter
*****

Registered: 2003-04-19
Posts: 4572
Loc: USA
This is possible, but an admin script that creates them would be much more secure.

As long as your clients are Win2k or higher, you can use a nested share, which eliminates the need to create a share for each user. For example: Set the share as \\server\share. Create the user folder under share, and connect to the share as \\server\share\user. Set the permissions for each user and you are done.
_________________________
(... better days ahead)

Top
#194669 - 2009-07-10 11:01 PM Re: Create and Map Hidden Shares [Re: Allen]
MadMills Offline
Just in Town

Registered: 2009-05-20
Posts: 2
Loc: Los Angeles, CA
Allen -
Thanks very much for the response. I guess I do not need to create shares, I can map the user directly to their respective folder, Agreed. I was more looking for a way for Kixtart to create these folders when the user logs in to keep from having to manually create each one. I think I found a way to do this - however I don't think there is a way to create permissions on the fly - even with WSH.

I will try and share the final results when complete.

Much appreciated.

Top
#194670 - 2009-07-11 01:55 AM Re: Create and Map Hidden Shares [Re: MadMills]
Glenn Barnas Administrator Offline
KiX Supporter
*****

Registered: 2003-01-28
Posts: 4402
Loc: New Jersey
If you create a share - \\server\users - for example, you grant that folder "Admins - Full Control", nothing else.

When you create users in ADU&C, you specify "\\server\users\%USERNAME%" as their home directory. The AD tool will create the folder and assign the user full-control rights on the folder that is created.

There's no need to script any of this..

Glenn
_________________________
Actually I am a Rocket Scientist! \:D

Top
#194673 - 2009-07-11 02:26 AM Re: Create and Map Hidden Shares [Re: Glenn Barnas]
NTDOC Administrator Offline
Administrator
*****

Registered: 2000-07-28
Posts: 11634
Loc: Space
Yeah, now all you have to do is go back and remove those full-control rights and set it back to MODIFY rights. No user should ever have FULL Control in my opinion. I don't want them changing rights on anything.
Top
#194680 - 2009-07-11 08:46 PM Re: Create and Map Hidden Shares [Re: NTDOC]
Glenn Barnas Administrator Offline
KiX Supporter
*****

Registered: 2003-01-28
Posts: 4402
Loc: New Jersey
I think the logic behind granting the home folder full control is that the user will be the only one creating things there.. and generally when you create something, you have full control automatically.

I'm just looking at a file I created in a "public" share where I have Modify rights.. I have full control on the file I just created. Thus, removing the rights on the home folders as you suggest seems counter-productive to some degree.

Of course, granting Full Control to any user/group other than Administrators outside of the home folder is "strictly Verboten!"

Glenn
_________________________
Actually I am a Rocket Scientist! \:D

Top
#194685 - 2009-07-12 07:03 AM Re: Create and Map Hidden Shares [Re: Glenn Barnas]
NTDOC Administrator Offline
Administrator
*****

Registered: 2000-07-28
Posts: 11634
Loc: Space
Well I'm just bitter from past experience with users that knew a little about NT and taking away our Admin rights to stop us from copying and managing stuff, what they didn't realize was that it also affected our backups. So we had to go back, take ownership and correct them again.

I'm reasonably certain (without actually investigating) that it is because again by default Creator/Owner is assigned full rights is why you were able to. I've removed that permission for many years now except for Exchange enabled objects as it actually caused problems.

However I don't think it is a security issue, at the time it was an annoyance and since then I've just been in the habit of restricting it.

Top
Page 1 of 1 1


Moderator:  Jochen, Allen, Radimus, Glenn Barnas, ShaneEP, Ruud van Velsen, Arend_, Mart 
Hop to:
Shout Box

Who's Online
0 registered and 1452 anonymous users online.
Newest Members
Viginette, ManuvdWielNL, Sir_Barrington, batdk82, StuTheCoder
17888 Registered Users

Generated in 0.064 seconds in which 0.031 seconds were spent on a total of 13 queries. Zlib compression enabled.

Search the board with:
superb Board Search
or try with google:
Google
Web kixtart.org