Author Topic: Users have full access to non authorized share  (Read 2373 times)

ddr400

  • Zen Apprentice
  • *
  • Posts: 15
  • Karma: +1/-0
    • View Profile
Users have full access to non authorized share
« on: May 19, 2013, 01:28:48 pm »
I'm having a serious problem in the Zentyal server.
After an component upgrade, my zentyal gives R/W access to all users to all shares (even the ones that don't have any acl defined).

Any ideas?

Best Regards

ddr400

  • Zen Apprentice
  • *
  • Posts: 15
  • Karma: +1/-0
    • View Profile
Re: Users have full access to non authorized share
« Reply #1 on: May 19, 2013, 06:14:41 pm »
I found that if an user are associated to the user group DOMAIN ADMINS, he could access in R/W to all zentyal server shares...

It's a bug or it is a configuration issue?


jbahillo

  • Zentyal Staff
  • Zen Hero
  • *****
  • Posts: 1444
  • Karma: +77/-2
    • View Profile
Re: Users have full access to non authorized share
« Reply #2 on: May 20, 2013, 09:18:20 am »
Hi there:

If that user is a domain admin, he will be able to acces any share, that's right and the intended way to be .

Note that this kind of user should only be used for joining a computer to a domain or similar uses (domain administration)

ddr400

  • Zen Apprentice
  • *
  • Posts: 15
  • Karma: +1/-0
    • View Profile
Re: Users have full access to non authorized share
« Reply #3 on: May 21, 2013, 01:51:42 pm »
Hi there,

If I need an user with installation rights only... what can I do to define that without insert that user in the Domain Admins?

Best Regards

jbahillo

  • Zentyal Staff
  • Zen Hero
  • *****
  • Posts: 1444
  • Karma: +77/-2
    • View Profile
Re: Users have full access to non authorized share
« Reply #4 on: May 21, 2013, 06:57:09 pm »
Hi there, do you need it for every pc? One possible solution could be inserting the user group (say installers) into the local computer admin group (for local I mean the group in that computer) through a GPO.