timbo343 Posted July 3, 2019 Posted July 3, 2019 (edited) A user has reported a strange issue in HAP where they are able to create and upload files and folders to their userarea however any shares they have access to they are unable to write to even though the access rights are applied as they should be. I have checked to make sure their user can be seen via the system by browsing to /HAP/api/ad/roles/*username* and this comes back as expected. The users all can access and edit the folders on the network without any issues. Is anybody able to offer any assistance - HAP has been rock solid for years. Thanks PS: just to add to this, it would appear if i leave the ENABLE WRITE TO box empty, i can still create new folders but the users cannot. Even adding ALL and ALL to both read and write fields, this doesn't have an affect on the users. Edited July 3, 2019 by timbo343
timbo343 Posted July 3, 2019 Author Posted July 3, 2019 It would seem something is broken in HAP with NTFS and Security Permissions on folders. I'm really struggling to get my head around what is and what isn't working.
nickbro Posted July 3, 2019 Posted July 3, 2019 make sure write checks are not on. What version of HAP+ are you on?
timbo343 Posted July 3, 2019 Author Posted July 3, 2019 Where are they Nick? I've got 3 different versions on the go for testing at the moment. It would seem that the windows folder and file security is causing issues when users try to either create new folders or delete. It would seem they need to have FULL access to the folders and users in groups aren't recognized either.
timbo343 Posted July 3, 2019 Author Posted July 3, 2019 make sure write checks are not on. What version of HAP+ are you on? I've found it, switched it to off on a 10.5 install. Will test now.
timbo343 Posted July 3, 2019 Author Posted July 3, 2019 (edited) So, ive done some testing to find out what is actually happening: Group: Staff User: Test Staff (who is also a member of Group Staff) Shared Folder: \\Shares\test Test folder \\shares\test\123456 HAP Setting: Perform Read/Write checks = Off Enable Read to: ALL Enable Write to: ALL Version of HAP - 10.5 Server OS: 2019 Test 1: The shared folder \\shares\test has the following permissions: - Windows Sharing Tab > Permissions > Group: Staff = Full - Security Tab > Group Staff = Full User Test Staff is unable to create / upload / delete / rename any items into \\shares\test or \\shares\test\123456 Test 2: The shared folder \\shares\test has the following permissions: - Windows Sharing Tab > Permissions > Group: Staff = Full - Security Tab > Test Staff = Full & Group Staff = Full User Test Staff is ABLE to create / upload / delete / rename items into \\shares\test or \\shares\test\123456. If user Test Staff creates any new items, they become the owner of those items. This shows to me the HAP does not recognise users that are embedded in to groups? Is this a fault within the system? Surely we cannot be expected to add each user individually to the security tab of each folder? Edited July 3, 2019 by timbo343
timbo343 Posted July 10, 2019 Author Posted July 10, 2019 (edited) After doing a bit more testing i have found out the following: This is the setting of group STAFF and TESTSTAFF is a member of the group STAFF - this is what we see: If I add TESTSTAFF to the SECURITY tab then this shows: @nickbro is this enough proof that AD groups does not work in Home Access Plus? I have tried this on version 10, 10.5 and 10.6 and this is the case for all versions. I would try version 9 if i had an install for it however i cannot seem to find version 9 on the net. Edited July 10, 2019 by timbo343
nickbro Posted July 10, 2019 Posted July 10, 2019 The groups should work, if when you query the API it tells you the groups it has it's something else. I know on our setup the folder shares are everyone full control then using NTFS to restrict it. It could be because the admin user doesn't have permission to that shared it can't parse the permissions
timbo343 Posted July 10, 2019 Author Posted July 10, 2019 The groups should work, if when you query the API it tells you the groups it has it's something else. I know on our setup the folder shares are everyone full control then using NTFS to restrict it. It could be because the admin user doesn't have permission to that shared it can't parse the permissions I don't want EVERYONE to be set in the Sharing permissions as this is potentially a security risk. Here is what i get when i query the API for TESTSTAFF:
nickbro Posted July 10, 2019 Posted July 10, 2019 To me then it looks like HAP+ isn't able to get the share permissions because the admin user doesn't have permission to the share/folder structure. The initial query is done via the admin user then it impersonates the other user
timbo343 Posted July 10, 2019 Author Posted July 10, 2019 To me then it looks like HAP+ isn't able to get the share permissions because the admin user doesn't have permission to the share/folder structure. The initial query is done via the admin user then it impersonates the other user Let me do a rebuild of the server on a new server and see what that gives, it's strange it's happening on all file servers across the domain when i set up test folders.
timbo343 Posted July 11, 2019 Author Posted July 11, 2019 @nickbro - it would seem after setting up a new test server the nested groups are working as expected. Looks like i'm going to have to ditch the server. I also have taken some notes on how to setup up HAP 10.5 on server 2019 so i will get them typed up and posted on here so others know how to get HAP setup as it seems a lot of first time users seem to struggle.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now