Confused with privileges (Users, User groups, shared folders)

FTP Server, File Server, DDNS, SAMBA, AFP, NFS
Post Reply
LRATOZ
New here
Posts: 3
Joined: Sun Apr 04, 2021 5:23 am

Confused with privileges (Users, User groups, shared folders)

Post by LRATOZ »

Hi,

I've got 2 QNAP boxes: TS-453D and a TS-669Pro.
I've been using the TS-669Pro since 2012 and it has been extremely reliable.
I purchased the TS-453D last year so that I could use the older machine purely for backup.
Anyway, our life situation has changed. Due to the corona virus situation our son and girlfriend moved back in with us.
Before that I had access to my files wide open but now I want to keep some folders hidden to others.

So, I set up a couple of users and folders but I'm confused with the different layers of permissions.
Let me explain:
I've got following hypothetical users: Admin, A, B, C
I've got following folders: Root, Multimedia, Shared, A, B, C and the compulsory home, homes, web

I want to allocate following privileges:
Admin has R/W access to all
A has R/W to Shared and A, has RO access to Multimedia and No Access to Root, B and C, home, homes, web
B has R/W to Shared and B, has RO access to Multimedia and No Access to Root, A and C, home, homes, web
C has R/W to Shared and C, has RO access to Multimedia and No Access to Root, A and B, home, homes, web
I only need one user group. Let's call it LAN-group.

I've been watching Youtube videos from NASCompares, as there isn't much else available, but that makes me even more confused.
The NAP manual covers every topic possible but doesn't give practicle examples.
I am computer savvy but no IT-expert.
So, my question to the forum is: What would be the best strategy to set this up? (And keep it as simple as possible).
Many thanks in advance and I hope somebody will be able to provide clear instructions.
Have a nice day!
Luke
Melbourne, Australia
User avatar
spile
Been there, done that
Posts: 641
Joined: Tue May 24, 2016 12:13 am

Re: Confused with privileges (Users, User groups, shared folders)

Post by spile »

The above is how I have my NAS setup. Different folders with different levels of permission for each user. What is the problem in implementing the strategy on your NAS?
User avatar
Moogle Stiltzkin
Guru
Posts: 11445
Joined: Thu Dec 04, 2008 12:21 am
Location: Around the world....
Contact:

Re: Confused with privileges (Users, User groups, shared folders)

Post by Moogle Stiltzkin »

i left mine as default most part. because the admin user should have access to everything.

it's when you create additional accounts should you begin lock those down further.

there is a setting for guest access. if you allow that, then no credentials will be asked, instead anyone on the network can then detect your nas on the network and access the shares. For security reasons, i do not allow guest access. I require credentials entered. So my admin account already requires this. for additional user accounts, they have to use their own credentials.

in shares you can designate which account users are allowed to access (detect these shares), read/write etc to those shares. this is another thing to setup.


there is info you can find online how this works

https://www.youtube.com/watch?v=eDicXy_ttg0

https://www.youtube.com/watch?v=vD_hziwGfo8



just be sure

1. you allow access to shares only if they should have access
2. you restrict if they are allowed to read, or write or both.
3. you decide if you allow guest access which requires no credentials or not. or whether you want to strictly only have each user have a login account which you can then keep track of better
4. after modifying permissions, TEST THEM. does it work as you configured it? always verify 8)

you don't want people seeing shares, or accessing them, or deleting stuff they should not be having access to. that is your goal :'
NAS
[Main Server] QNAP TS-877 (QTS) w. 4tb [ 3x HGST Deskstar NAS & 1x WD RED NAS ] EXT4 Raid5 & 2 x m.2 SATA Samsung 850 Evo raid1 +16gb ddr4 Crucial+ QWA-AC2600 wireless+QXP PCIE
[Backup] QNAP TS-653A (Truenas Core) w. 4x 2TB Samsung F3 (HD203WI) RaidZ1 ZFS + 8gb ddr3 Crucial
[^] QNAP TL-D400S 2x 4TB WD Red Nas (WD40EFRX) 2x 4TB Seagate Ironwolf, Raid5
[^] QNAP TS-509 Pro w. 4x 1TB WD RE3 (WD1002FBYS) EXT4 Raid5
[^] QNAP TS-253D (Truenas Scale)
[Mobile NAS] TBS-453DX w. 2x Crucial MX500 500gb EXT4 raid1

Network
Qotom Pfsense|100mbps FTTH | Win11, Ryzen 5600X Desktop (1x2tb Crucial P50 Plus M.2 SSD, 1x 8tb seagate Ironwolf,1x 4tb HGST Ultrastar 7K4000)


Resources
[Review] Moogle's QNAP experience
[Review] Moogle's TS-877 review
https://www.patreon.com/mooglestiltzkin
User avatar
Moogle Stiltzkin
Guru
Posts: 11445
Joined: Thu Dec 04, 2008 12:21 am
Location: Around the world....
Contact:

Re: Confused with privileges (Users, User groups, shared folders)

Post by Moogle Stiltzkin »

as for the default shares created by qnap, there is an explanation about that
viewtopic.php?t=88997#p391961

viewtopic.php?t=102673#p459681


things like home/homes i don't even use them. i create my own shares and use those instead. that said, you shouldn't delete those default shares qnap creates. you can just simply ignore.



there is also a network recycle bin. i didn't want that so i disabled it and cleared recycle bin to regain any space. i use snapshots as a replacement for recycle bin, or refer to my backup.
NAS
[Main Server] QNAP TS-877 (QTS) w. 4tb [ 3x HGST Deskstar NAS & 1x WD RED NAS ] EXT4 Raid5 & 2 x m.2 SATA Samsung 850 Evo raid1 +16gb ddr4 Crucial+ QWA-AC2600 wireless+QXP PCIE
[Backup] QNAP TS-653A (Truenas Core) w. 4x 2TB Samsung F3 (HD203WI) RaidZ1 ZFS + 8gb ddr3 Crucial
[^] QNAP TL-D400S 2x 4TB WD Red Nas (WD40EFRX) 2x 4TB Seagate Ironwolf, Raid5
[^] QNAP TS-509 Pro w. 4x 1TB WD RE3 (WD1002FBYS) EXT4 Raid5
[^] QNAP TS-253D (Truenas Scale)
[Mobile NAS] TBS-453DX w. 2x Crucial MX500 500gb EXT4 raid1

Network
Qotom Pfsense|100mbps FTTH | Win11, Ryzen 5600X Desktop (1x2tb Crucial P50 Plus M.2 SSD, 1x 8tb seagate Ironwolf,1x 4tb HGST Ultrastar 7K4000)


Resources
[Review] Moogle's QNAP experience
[Review] Moogle's TS-877 review
https://www.patreon.com/mooglestiltzkin
User avatar
OneCD
Guru
Posts: 12146
Joined: Sun Aug 21, 2016 10:48 am
Location: "... there, behind that sofa!"

Re: Confused with privileges (Users, User groups, shared folders)

Post by OneCD »

Moogle Stiltzkin wrote: Sun Apr 04, 2021 5:05 pm as for the default shares created by qnap, there is an explanation about that
Although, I recently noticed (in QTS 4.5.2 at-least), the only default shares are 'Public' and 'Web'. ;)

ImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImageImage
User avatar
Moogle Stiltzkin
Guru
Posts: 11445
Joined: Thu Dec 04, 2008 12:21 am
Location: Around the world....
Contact:

Re: Confused with privileges (Users, User groups, shared folders)

Post by Moogle Stiltzkin »

hm.... the next time i reinit, i'll pay attention to these changes o-O;
NAS
[Main Server] QNAP TS-877 (QTS) w. 4tb [ 3x HGST Deskstar NAS & 1x WD RED NAS ] EXT4 Raid5 & 2 x m.2 SATA Samsung 850 Evo raid1 +16gb ddr4 Crucial+ QWA-AC2600 wireless+QXP PCIE
[Backup] QNAP TS-653A (Truenas Core) w. 4x 2TB Samsung F3 (HD203WI) RaidZ1 ZFS + 8gb ddr3 Crucial
[^] QNAP TL-D400S 2x 4TB WD Red Nas (WD40EFRX) 2x 4TB Seagate Ironwolf, Raid5
[^] QNAP TS-509 Pro w. 4x 1TB WD RE3 (WD1002FBYS) EXT4 Raid5
[^] QNAP TS-253D (Truenas Scale)
[Mobile NAS] TBS-453DX w. 2x Crucial MX500 500gb EXT4 raid1

Network
Qotom Pfsense|100mbps FTTH | Win11, Ryzen 5600X Desktop (1x2tb Crucial P50 Plus M.2 SSD, 1x 8tb seagate Ironwolf,1x 4tb HGST Ultrastar 7K4000)


Resources
[Review] Moogle's QNAP experience
[Review] Moogle's TS-877 review
https://www.patreon.com/mooglestiltzkin
Post Reply

Return to “File Sharing”