NMR uses SFS shares to enable researchers to copy files from instrument computers (Windows and Linux) to their own computers (Windows, MacOS. Any Linux?!)
Instructions for using group's file share.

GC Mate's account is a single user account, <AS-CHM-GCMate>.

Behavior desired on GCMate computer (Windows):

  • Browse entire NMR file share, listing all contents.
  • Permit files to be written anywhere in the NMR file share.
  • Not allow any files on the NMR file share to be opened, executed, deleted, moved, etc.

Account

Who

Comments

NMR Root Folder
Permissions

Group Folder
Permissions

User Folder
Permissions

AS-CHM-NMR-ADM

Acct - NMR Special Admin
(currently Ivan )

See "AS-CHM-NMR-ShareAdmin" group account.

n/a

n/a

n/a

AS-CHM-NMR-ShareAdmin

Group - NMR machine admin accounts.
Includes NMR-ADM and AMC88-ADM accounts

7/2/15: Oliver had Tony use his ADM account and he was able to get into the NMR file share and see all. Great! See "Old info" below for a "to do".

Old info: Oliver never got the AMC88-ADM account to work. (The NMR-ADM account worked fine.) Why is one working, but not the other?
If we get the AMC88-ADM account to work, consider creating one for Ivan so not to overload his NMR-ADM account (remove the NMR-ADM account).

Modify

Modify

Modify

AS-CHM-NMR-ShareGroup

Groups - Research Group members

 

Ideal: List folders, gaining access only to their group's folder. But don't do if increases by too much the complexity of admin'ing share or de-bugging share issues. (Inheritance issues.)
Acceptable alternative: No access. In this case, users will have to remember to add "/GroupName" to their UNC path.

Modify

Modify

AS-Chemistry-IT

Group - Chemistry IT

Q: Best if not use our normal NetID-based AD account, and reserve those accounts as a "normal" user?
Idea:
(1) Add a "-NMR-ShareChemIT" group with our NetIDs.
(2) Add our -DOC accounts to the existing "-NMR-ShareAdmin",
(3) Remove AS-CHM-Chemistry-IT from this NMR share.

Full

Full

Full

AS-CHM-NMR-ShareInstAccts
Group members:
AS-CHM-GCMate
AS-CHM-NMRINST1

Acct - Instrument Account

Currently OK, but not ideal: Although a file can't be copied or opened, it can be replaced with an identically named file.

Folders, sub-folders and files: Write only

Write only

Write only

AS-CHM-NMR-ShareInstAccts
Group members:
AS-CHM-GCMate
AS-CHM-NMRINST1

Acct - Instrument Account

Currently OK, but not ideal: Although a new folder can be created, it can't be named by the user. Only "New Folder" (or "New Folder (2)", etc.) get created.
Currently goodL Although folders can't be renamed or deleted, contents can be merged with an identically named folder.

Folder and sub-folders: List folder contents

List folder contents

List folder contents

AS-CHM-NMR-SharePublic

Group - Researchers without an account

For ad hoc users to pick up their data (read-only; no write/ delete). Must have their NetID credentials, but that's it. They don't have to be added to an AD group, etc.
Files must be reviewed and deleted by Ivan (an Admin and resource steward).

See this section for "AS-CHM-NMR-ShareGroup", above.
In this case, the acceptable alternative is: No access. Analogous to the above, users will have to remember to add "/Public" to their UNC path.

Read & execute

Read & execute

For testing

Account

Purpose

AS-CHM-NMRINST1

Test account. To be used as a test instrument account to write to the SFS drive from Linux.

AS-CHM-ChemITsfs

A user testing account for ChemIT staff since their non-DOC accounts have too many privileges in SFS-land.

Permissions setting

Oliver set these permission for AS-CHM-NMR-ShareInstAccts to get the almost-perfect permissions on the GCMate computer:

Allow:

  • List folder contents
  • Write

Setting the above permission in turn creates two entries for AS-CHM-NMR-ShareInstAccts under the Advanced security settings. Click on the links to get a screen-shot of the detailed permissions:

Note: The detailed permission settings are created when one just selects "List folder contents" and "Write". Fortunately one doesn't have to hand-select these detailed (Advanced) permissions, and they are simply documented here as an FYI.

  • No labels