Access-Based Enumeration Question
We have a DFS structure and they want to hide DFS links to users that don't have access. That is fine, we can use ABE to hide those DFS links. The thing is, they also have a lot of folders with List Folder Contents only and not allowing users read. This way help desk cannot read files, but they can see the files in case they need to restore those files. The only problem, is ABE is actually hiding those files because those helpdesk users do not have read access to those files, only list folder contents. Is there any way to set ABE to only work on folders instead of the files as well? Thanks!
“For success, attitude is equally as important as ability.” - Harry F. Banks
Comments
-
blargoe Member Posts: 4,174 ■■■■■■■■■□For any given share, it's all or none. You can't tell it to work for only files or only folders.IT guy since 12/00
Recent: 11/2019 - RHCSA (RHEL 7); 2/2019 - Updated VCP to 6.5 (just a few days before VMware discontinued the re-cert policy...)
Working on: RHCE/Ansible
Future: Probably continued Red Hat Immersion, Possibly VCAP Design, or maybe a completely different path. Depends on job demands... -
royal Member Posts: 3,352 ■■■■□□□□□□blargoe wrote:For any given share, it's all or none. You can't tell it to work for only files or only folders.
Ya, that is what I kind of figured. If only ABE would let you pick folders, files, or both.“For success, attitude is equally as important as ability.” - Harry F. Banks -
royal Member Posts: 3,352 ■■■■□□□□□□Looks like our only option is to re-share that specific directory that is pretty deep down and have that one department directly connect to that share and just disable ABE on it. We're currently doing a Novell migration for them and one of their things is they don't want any user downtime and they want things to appear the exam same as it did in Novell to their users. This includes hiding anything they do not access to. They do have certain files though that they want displayed but not allow users to read. It's in this case that we are just going to have to share these folders and disable ABE so ABE won't hide those files due to them not having the permission to read.“For success, attitude is equally as important as ability.” - Harry F. Banks