Question
How can I perform configuration and verification on the host after Access Based Enumeration (ABE) is enabled when the storage system creates a CIFS share?
Answer
After ABE is enabled, the share directory does not display files or file folders on which the user has no access permission. The following shows accessing a CIFS share on the host in the domain environment (also applicable to local authentication users).
1. The host accesses the CIFS share created by the storage system successfully. Figure 1-1 shows share access by domain user aduser00.
Figure 1-1 The host accesses the CIFS share created by the storage system
![]()
2. Create file test.txt under the share path. Figure 1-2 shows the result.
Figure 1-2 Create file under the share path
![]()
3. Add permissions to domain users aduser01 and 24aduser1 and remove the default permission of Everyone. If the default permission of Everyone is not removed, all users have full control over the file and can still view the file.
Figure 1-3 shows how to modify the advanced settings of test.txt.
Figure 1-3 Modify the advanced settings
![]()
Figure 1-4 shows the advanced security settings before the default permission of Everyone is removed.
Figure 1-4 Before the default permission of Everyone is removed
![]()
Figure 1-5 shows the advanced security settings after the default permission of Everyone is removed.
Figure 1-5 After the default permission of Everyone is removed
![]()
Figure 1-6 shows the permission settings for domain user aduser01.
Figure 1-6 Permission settings for domain user aduser01
![]()
Figure 1-7 shows how to select read data, read attributes, read extended attributes, and read permissions to gain full read permissions.
Figure 1-7 Full read permissions
![]()
Figure 1-8 shows the permission settings for domain user 24aduser1.
Figure 1-8 Permission settings for domain user 24aduser1
![]()
4. View and check the files in the share path as domain users aduser01 and 24aduser1. The verification results are as follows:
Figure 1-9 shows the verification results for domain user aduser01.
Figure 1-9 Verification results for domain user aduser01
![]()
Figure 1-10 shows the verification results for domain user 24aduser1.
Figure 1-10 Verification results for domain user 24aduser1
![]()
This post was last edited by Chrisxl at 2018-08-13 02:00.