Build role-based access on a shared folder and test effective permissions
Task
Set up role-based access for a shared project folder on lin-srv: groups for the roles, a folder whose new files inherit the right group and permissions, and a read-only role granted through an ACL. Then log in as a member of each role and test what each can actually do, because effective permissions are what the system enforces, not what was intended.
Steps
- Create groups
proj-editandproj-read, and usersalice(edit),bob(read) andcarol(neither). - Create
/srv/projectowned by root and groupproj-edit, mode 2770 so new files inherit the group, and add default and access ACLs givingproj-readread and execute. Savegetfacl /srv/projecttolab/rbac/acl.txt. - As alice, create a file in the folder. Save
ls -lof it andgetfaclof it tolab/rbac/inherited.txt. - As each of alice, bob and carol, try to read the file and to create a new one. Record each attempt in
lab/rbac/tests.csvwith headeruser,action,expected,result, writing the expected result before trying. - Record in
lab/rbac/service.txthow a service account for a backup agent should be set up for this folder: its group, its shell and its rights.
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
grep -c 'group:proj-read:r-x' lab/rbac/acl.txt
grep -c 'default:group:proj-read' lab/rbac/acl.txt
grep -c 'proj-edit' lab/rbac/inherited.txt
awk -F, 'NR>1 && $3!=$4 {print "UNEXPECTED: "$0}' lab/rbac/tests.csv
awk -F, 'NR>1 {n++} END {print n" test(s)"}' lab/rbac/tests.csv
grep -Eic 'nologin|no shell|read|least' lab/rbac/service.txt
The folder carries both the access ACL and the default ACL, and alice's new file inherited the proj-edit group. Six tests, with no unexpected results: alice reads and writes, bob reads only, carol does neither. An unexpected result is the point of testing -- it is a permission that differs from the design.
Notes
The setgid bit (the 2 in 2770) is what makes new files take the folder's group instead of the creator's own. Without it, a file alice creates belongs to her personal group, and bob cannot read it despite the ACL.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.