Administrator Guide

Una ACL describe las entidades a las que se permite acceder a un recurso específico. Las ACL son un mecanismo de
control de acceso integrado en los sistemas operativos Windows. La compatibilidad con ACL en el sistema DR Series se
diferencia por cómo afecta a los dos tipos de contenedores siguientes:
Contenedores nuevos
Contenedores existentes
NOTA: El sistema DR Series admite configurar permisos a nivel de recurso compartido para un recurso compartido
CIFS que utilice una herramienta administrativa de Microsoft Windows. Los permisos a nivel de recurso
compartido le permiten controlar el acceso a los recursos compartidos. Para obtener más información, ver
Configuración de la seguridad a nivel de recurso compartido.
NOTA: Cualquier usuario que forme parte de BUILTIN\Administrators puede editar ACL en recursos compartidos
CIFS. El administrador del sistema DR Series local está incluido en el grupo BUILTIN\Administrators. Para agregar
grupos de dominios adicionales en BUILTIN\Administrators, puede utilizar la herramienta Computer Manager
(Administrador de equipos) en un cliente de Windows para conectar con el sistema DR Series como Administrador
de dominio y agregar cualquier grupo que desee. La capacidad permite que usuarios distintos al Administrador de
dominio puedan modificar un ACL si es necesario.
Access Control List Support in Containers
All containers created with the 1.1 release and later versions of the DR4000 system software (or pre–1.1 version system
software that was upgraded to 1.1 or later), applies a default Access Control List (ACL) at the root of the container. This
default ACL is the same as that which would be created by a Microsoft Windows 2003 Server. Therefore, these new
containers with the default ACL support the following permission types:
NOTA: Any user that is part of BUILTIN\Administrators can edit ACLs on CIFS shares. The local DR Series system
administrator is included in the BUILTIN\Administrators group. To add additional domain groups to the BUILTIN
\Administrators group, you can use the Computer Manager tool on a Windows client to connect to the DR Series
system as Domain administrator and add any groups you want. This capability allows users other than the Domain
administrator to modify an ACL as needed.
BUILTIN\Administrators:
Allows Full access, object inherit, and container inherit.
Applies to This folder, subfolders, and files.
CREATOR OWNER:
Allows Full access, inherit only, object inherit, and container inherit.
Applies to Subfolders and files only.
EVERYONE:
Allows Traverse folders, execute files, list folders, read data, read attributes, and read
extended attributes.
Applies to This folder only.
NT AUTHORITY\SYSTEM:
Allows Full access, object inherit, and container inherit.
Applies to This folder, subfolders, and files.
BUILTIN\Users:
Allows Create folders and append data, inherit-only, and container inherit.
23