Click here to get back home

Why Are List Folder / Read Data Combined?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Why Are List Folder / Read Data Combined? Will 11-21-2005
Posted by Will on November 21, 2005, 10:45 pm
Please log in for more thread options
Why are List Folder and Read Data combined into a single privilege? They
seem like very distinct things, and I can imagine cases where I would want
users to be able to see the files inside a folder (List Folder) but I would
not want them to be able to read data in the files they list. The current
design of ACLs doesn't let you set a permission in the folder that *new*
files created in the folder will automatically inherit. Instead it looks
like you have to set one ACL for the folder and then come and manually set
permissions for files in the folder. That quickly becomes completely
unmanageable in a large file tree. You like to have ACLs inherit as much
as possible.

--
Will



Posted by Roger Abell [MVP] on November 22, 2005, 12:46 am
Please log in for more thread options

> Why are List Folder and Read Data combined into a single privilege?

They are two differenct privileges.
They use the same bit in the bitmask, but it is interpreted
differently depending on the object - file or folder.
You can specific where the ACE carrying the mask is
applicable to files, to folders, or both.

>They seem like very distinct things,

they are

> and I can imagine cases where I would want
> users to be able to see the files inside a folder (List Folder) but I
> would
> not want them to be able to read data in the files they list.

absolutely !

> The current
> design of ACLs doesn't let you set a permission in the folder that *new*
> files created in the folder will automatically inherit. Instead it looks
> like you have to set one ACL for the folder and then come and manually set
> permissions for files in the folder.

??? not sure I follow you at all here.
Have you used the Advanced button in the NTFS dialog?
If so, did you try highlighting a ACE and clicking Edit?
In there, notice the dropbox at the top that controls the
object the ACE is applicable to ?

> That quickly becomes completely
> unmanageable in a large file tree. You like to have ACLs inherit as much
> as possible.
>
> --
> Will
>
>



Posted by Will on November 22, 2005, 1:35 am
Please log in for more thread options
Wow, until just now I didn't understand that I could use the same user
object more than once in a single ACL. It does get a little complex but at
least it can be done. Thanks for the education.

--
Will


> > The current
> > design of ACLs doesn't let you set a permission in the folder that *new*
> > files created in the folder will automatically inherit. Instead it
looks
> > like you have to set one ACL for the folder and then come and manually
set
> > permissions for files in the folder.
>
> ??? not sure I follow you at all here.
> Have you used the Advanced button in the NTFS dialog?
> If so, did you try highlighting a ACE and clicking Edit?
> In there, notice the dropbox at the top that controls the
> object the ACE is applicable to ?



Posted by Roger Abell [MVP] on November 22, 2005, 1:17 pm
Please log in for more thread options
No problem Will. The ACL structures are actually fairly
involved, considering that they are examined all the time.
IMO this is one aspect of the OS that people fail to fully
appreciate, that there is so much overhead handled without
that large of a performance hit, and of just how flexible
and dare I say rich the declarative security of ACLing is
compared to the limited form of same in say *nix OSs.

> Wow, until just now I didn't understand that I could use the same user
> object more than once in a single ACL. It does get a little complex but
> at
> least it can be done. Thanks for the education.
>
> --
> Will
>
>
>> > The current
>> > design of ACLs doesn't let you set a permission in the folder that
>> > *new*
>> > files created in the folder will automatically inherit. Instead it
> looks
>> > like you have to set one ACL for the folder and then come and manually
> set
>> > permissions for files in the folder.
>>
>> ??? not sure I follow you at all here.
>> Have you used the Advanced button in the NTFS dialog?
>> If so, did you try highlighting a ACE and clicking Edit?
>> In there, notice the dropbox at the top that controls the
>> object the ACE is applicable to ?
>
>



Posted by Steven L Umbach on November 22, 2005, 5:56 pm
Please log in for more thread options
A good example of this is the root/drive folder. Look at advanced
permissions and you will users listed three times [at least on XP
o]. --- Steve


> Wow, until just now I didn't understand that I could use the same user
> object more than once in a single ACL. It does get a little complex but
> at
> least it can be done. Thanks for the education.
>
> --
> Will
>
>
>> > The current
>> > design of ACLs doesn't let you set a permission in the folder that
>> > *new*
>> > files created in the folder will automatically inherit. Instead it
> looks
>> > like you have to set one ACL for the folder and then come and manually
> set
>> > permissions for files in the folder.
>>
>> ??? not sure I follow you at all here.
>> Have you used the Advanced button in the NTFS dialog?
>> If so, did you try highlighting a ACE and clicking Edit?
>> In there, notice the dropbox at the top that controls the
>> object the ACE is applicable to ?
>
>



Similar ThreadsPosted
ACLs - Users with READ can MOVE a whole folder? April 11, 2007, 10:45 am
Remove List Folder access only? March 16, 2006, 2:18 am
Data Access. July 29, 2007, 7:18 pm
execute but no copy or read April 26, 2006, 2:58 am
Deleting Data permanently November 1, 2005, 10:17 am
Big (please read HUGE) problem in the network October 12, 2007, 5:16 am
BitLocker Data Volume Encryption March 30, 2007, 2:36 pm
data security policy examples July 19, 2008, 7:05 pm
"Read-Only" branch office domain controllers? April 20, 2006, 2:34 am
Unable to read any security database file February 7, 2007, 2:31 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap