Build role-based access on a shared folder and test effective permissions

short · 45 min · Objective 3.3

Task

Set up role-based access for a shared project folder on lin-srv: groups for the roles, a folder whose new files inherit the right group and permissions, and a read-only role granted through an ACL. Then log in as a member of each role and test what each can actually do, because effective permissions are what the system enforces, not what was intended.

Steps

  1. Create groups proj-edit and proj-read, and users alice (edit), bob (read) and carol (neither).
  2. Create /srv/project owned by root and group proj-edit, mode 2770 so new files inherit the group, and add default and access ACLs giving proj-read read and execute. Save getfacl /srv/project to lab/rbac/acl.txt.
  3. As alice, create a file in the folder. Save ls -l of it and getfacl of it to lab/rbac/inherited.txt.
  4. As each of alice, bob and carol, try to read the file and to create a new one. Record each attempt in lab/rbac/tests.csv with header user,action,expected,result, writing the expected result before trying.
  5. Record in lab/rbac/service.txt how a service account for a backup agent should be set up for this folder: its group, its shell and its rights.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

grep -c 'group:proj-read:r-x' lab/rbac/acl.txt
grep -c 'default:group:proj-read' lab/rbac/acl.txt
grep -c 'proj-edit' lab/rbac/inherited.txt
awk -F, 'NR>1 && $3!=$4 {print "UNEXPECTED: "$0}' lab/rbac/tests.csv
awk -F, 'NR>1 {n++} END {print n" test(s)"}' lab/rbac/tests.csv
grep -Eic 'nologin|no shell|read|least' lab/rbac/service.txt

The folder carries both the access ACL and the default ACL, and alice's new file inherited the proj-edit group. Six tests, with no unexpected results: alice reads and writes, bob reads only, carol does neither. An unexpected result is the point of testing -- it is a permission that differs from the design.

Notes

The setgid bit (the 2 in 2770) is what makes new files take the folder's group instead of the creator's own. Without it, a file alice creates belongs to her personal group, and bob cannot read it despite the ACL.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.