← NAS: shares, permissions, and operations
02 / 6 · 40 MIN

Identity and permissions

Distinguish authentication, share access, and effective file permissions.

Concept and mechanism

The displayed identity is not always the identity used for remote access. In NFS AUTH_SYS, numeric UID and GID participate in authorization; the same username on two systems can correspond to different numbers. After reinstallation, reconcile those identifiers with ownership and policy without granting global writing to hide the mismatch. root_squash maps uid/gid-zero requests to the configured anonymous identity. Client root therefore does not imply root on the exporting server. all_squash has a different scope: it maps all identities. Analyze the effective mechanism before changing permissions or recommending more privileged accounts.

Guided application

In Samba, valid users allows service access but does not automatically grant every file operation. The host continues to limit the effective identity rights. If the account belongs to both valid users and invalid users, service access is denied. Another precedence needs care: write list can permit writing despite read only=yes while other applicable controls remain. Do not conclude a share is read-only from one parameter. In a fictional case, an administrator can write but the scheduler cannot; compare account, groups, share policy, and underlying permissions. Validate correction using the scheduled account and only approved operations.

IN PRACTICE

Same aps name, different UIDs: diagnosis must inspect the identity actually transmitted.

Common pitfalls

Name as UID; local root as remote root; valid users as global writing; isolated read only as complete policy.

Related topics: Shares and mounting · Security and write acknowledgement · Caching, timeouts, and uncertainty

Take this idea with you

Reconciling identity and authorization avoids excessive permissions and false fixes.

Create account

Reference: Linux NFS export policy and identity mapping · DR NAS 2026-09; selected Linux NFS, Samba, Windows SMB and ONTAP behavior