Access-Based Enumeration Question

royalroyal Member Posts: 3,352 ■■■■□□□□□□
We have a DFS structure and they want to hide DFS links to users that don't have access. That is fine, we can use ABE to hide those DFS links. The thing is, they also have a lot of folders with List Folder Contents only and not allowing users read. This way help desk cannot read files, but they can see the files in case they need to restore those files. The only problem, is ABE is actually hiding those files because those helpdesk users do not have read access to those files, only list folder contents. Is there any way to set ABE to only work on folders instead of the files as well? Thanks!
“For success, attitude is equally as important as ability.” - Harry F. Banks

Comments

  • blargoeblargoe Member Posts: 4,174 ■■■■■■■■■□
    For any given share, it's all or none. You can't tell it to work for only files or only folders.
    IT guy since 12/00

    Recent: 11/2019 - RHCSA (RHEL 7); 2/2019 - Updated VCP to 6.5 (just a few days before VMware discontinued the re-cert policy...)
    Working on: RHCE/Ansible
    Future: Probably continued Red Hat Immersion, Possibly VCAP Design, or maybe a completely different path. Depends on job demands...
  • royalroyal Member Posts: 3,352 ■■■■□□□□□□
    blargoe wrote:
    For any given share, it's all or none. You can't tell it to work for only files or only folders.

    Ya, that is what I kind of figured. If only ABE would let you pick folders, files, or both.
    “For success, attitude is equally as important as ability.” - Harry F. Banks
  • royalroyal Member Posts: 3,352 ■■■■□□□□□□
    Looks like our only option is to re-share that specific directory that is pretty deep down and have that one department directly connect to that share and just disable ABE on it. We're currently doing a Novell migration for them and one of their things is they don't want any user downtime and they want things to appear the exam same as it did in Novell to their users. This includes hiding anything they do not access to. They do have certain files though that they want displayed but not allow users to read. It's in this case that we are just going to have to share these folders and disable ABE so ABE won't hide those files due to them not having the permission to read.
    “For success, attitude is equally as important as ability.” - Harry F. Banks
Sign In or Register to comment.