|
||||||||
|
|
|||||||
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|
Hi,
I have a WS2003 AD domain and everything works fine including shares on the server. However, I am adding a few of the network capable media devices onto the network but unfortunately, they can only access public network shares (no ACL). Is it possible to setup a share on the WS2003 AD to be publicly accessible? (ie accessible without logon from non-domained machines/devices) I understand this will become a security issue but the network is for home use so I am not TOO bothered by it. Anybody can shed some light on this? Help much appreciated. ML |
|
#2
|
|||
|
|||
|
Greetings,
Give permissions for EVERYONE on your share. Then AD will just allow anyone to connect. Hope this helps, -- Louis Vitiello Jr. ------------------------------ MCSE, MCSA, MCP, A+/N+ ERCP XP Pro / Net Concepts "ML" <(E-Mail Removed)> wrote in message news:Ox$(E-Mail Removed)... > Hi, > I have a WS2003 AD domain and everything works fine including shares on > the server. However, I am adding a few of the network capable media > devices onto the network but unfortunately, they can only access public > network shares (no ACL). Is it possible to setup a share on the WS2003 AD > to be publicly accessible? (ie accessible without logon from non-domained > machines/devices) > > I understand this will become a security issue but the network is for home > use so I am not TOO bothered by it. > > Anybody can shed some light on this? Help much appreciated. > |
|
#3
|
|||
|
|||
|
Unfortunately, this only works on domained machines. Logon dialog still
pops up on non-domained XP machines and Linux boxes (Fedora core 5). So media boxes without network logon capability still cannot see the shares. "Louis Vitiello Jr." <louv-(E-Mail Removed)> wrote in message news:(E-Mail Removed)... > Greetings, > > Give permissions for EVERYONE on your share. Then AD will just allow > anyone to connect. > > Hope this helps, > -- > Louis Vitiello Jr. > ------------------------------ > MCSE, MCSA, MCP, A+/N+ > ERCP XP Pro / Net Concepts > > "ML" <(E-Mail Removed)> wrote in message > news:Ox$(E-Mail Removed)... >> Hi, >> I have a WS2003 AD domain and everything works fine including shares >> on the server. However, I am adding a few of the network capable media >> devices onto the network but unfortunately, they can only access public >> network shares (no ACL). Is it possible to setup a share on the WS2003 >> AD to be publicly accessible? (ie accessible without logon from >> non-domained machines/devices) >> >> I understand this will become a security issue but the network is for >> home use so I am not TOO bothered by it. >> >> Anybody can shed some light on this? Help much appreciated. >> > > |
|
#4
|
|||
|
|||
|
That's strange. Anycase, if the logon credentials match the users local
credentials then it should work as well. Make sure when you added share permissions for everyone you granted security rights as well. That might be causing a problem. Hope this helps, -- Louis Vitiello Jr. ------------------------------ MCSE, MCSA, MCP, A+/N+ ERCP XP Pro / Net Concepts "ML" <(E-Mail Removed)> wrote in message news:(E-Mail Removed)... > Unfortunately, this only works on domained machines. Logon dialog still > pops up on non-domained XP machines and Linux boxes (Fedora core 5). So > media boxes without network logon capability still cannot see the shares. > > "Louis Vitiello Jr." <louv-(E-Mail Removed)> wrote in message > news:(E-Mail Removed)... >> Greetings, >> >> Give permissions for EVERYONE on your share. Then AD will just allow >> anyone to connect. >> >> Hope this helps, >> -- >> Louis Vitiello Jr. >> ------------------------------ >> MCSE, MCSA, MCP, A+/N+ >> ERCP XP Pro / Net Concepts >> >> "ML" <(E-Mail Removed)> wrote in message >> news:Ox$(E-Mail Removed)... >>> Hi, >>> I have a WS2003 AD domain and everything works fine including shares >>> on the server. However, I am adding a few of the network capable media >>> devices onto the network but unfortunately, they can only access public >>> network shares (no ACL). Is it possible to setup a share on the WS2003 >>> AD to be publicly accessible? (ie accessible without logon from >>> non-domained machines/devices) >>> >>> I understand this will become a security issue but the network is for >>> home use so I am not TOO bothered by it. >>> >>> Anybody can shed some light on this? Help much appreciated. >>> >> >> > > |
|
#5
|
|||
|
|||
|
Louis Vitiello Jr. wrote:
> That's strange. It's Windows 2003. http://www.windowsecurity.com/articl..._Everyone.html -- -- Rob Moir, Microsoft MVP Blog Site - http://www.robertmoir.com Virtual PC 2004 FAQ - http://www.robertmoir.co.uk/win/VirtualPC2004FAQ.html I'm always surprised at "professionals" who STILL have to be asked "Have you checked (event viewer / syslog)". |
|
#6
|
|||
|
|||
|
Does this mean if I specifically gives Anonymous Login read, list, and
execute permission, the media box (linux based) will be able to access the share without credentials? "Robert Moir" <robspamtrap+(E-Mail Removed)> wrote in message news:(E-Mail Removed)... > Louis Vitiello Jr. wrote: >> That's strange. > > It's Windows 2003. > http://www.windowsecurity.com/articl..._Everyone.html > > > -- > -- > Rob Moir, Microsoft MVP > Blog Site - http://www.robertmoir.com > Virtual PC 2004 FAQ - > http://www.robertmoir.co.uk/win/VirtualPC2004FAQ.html > I'm always surprised at "professionals" who STILL have to be asked "Have > you checked (event viewer / syslog)". > |
|
#7
|
|||
|
|||
|
ML wrote:
> Does this mean if I specifically gives Anonymous Login read, list, and > execute permission, the media box (linux based) will be able to > access the share without credentials? It probably would but i haven't tried it myself. I have changed the everyone group as described in the article i link to and had it work fine. |
|
#8
|
|||
|
|||
|
Finally solved. Turns out that the media box is using the account "root"
with no password to access network shares. So I created this account in AD, taking care to give it as little permission as possible (remove from all groups). And I have to change the policies to make Digital signing of SMB optional instead of required. Now everything works. Unfortunately, this means that the media box is STILL AUTHENTICATING to my AD server and thus probably will need a device CAL..... Sucks...... "Robert Moir" <robspamtrap+(E-Mail Removed)> wrote in message news:(E-Mail Removed)... > ML wrote: >> Does this mean if I specifically gives Anonymous Login read, list, and >> execute permission, the media box (linux based) will be able to >> access the share without credentials? > > It probably would but i haven't tried it myself. I have changed the > everyone group as described in the article i link to and had it work fine. > |
![]() |
| Tags |
| folder, public, server, share, ws2003 |
| Thread Tools | |
| Display Modes | |
|
|