Creating a Local Authentication User Group

This section describes how to create a local authentication user group. Local authentication user groups are used to control the share access permissions of specific local authentication users.

Context

A system has nine local authentication user groups that are automatically created. The nine user groups are reserved for the system and cannot be modified or deleted.

An access control list (ACL) is a collection of permissions that are authorized to users or user groups to operate shared files. ACL permissions are classified into ACL storage permissions and ACL authentication permissions. After a user logs in to a share, the system determines the user's permissions on the share, reads the ACL permissions, and then determines whether the user can read and write files. For ACL storage permissions, each ACL permission is called an Access Control Entry (ACE). After a CIFS share is mounted to a Windows client, the client sends NT ACLs to the server (storage device that provides the CIFS share).

Procedure

  1. Choose Resources > Access > Authentication User > Windows Users > Local Authentication User Group.
  2. Select a desired account from the Account drop-down list in the upper left corner.
  3. Click Create.

    The Create Local Windows Authentication User Group page is displayed on the right.

  4. Set basic parameters for the local authentication user group.

    Table 1 describes related parameters.

    Table 1 Basic local authentication user group parameters

    Parameter

    Description

    Name

    Name of the local authentication user group.

    [Value range]

    • The name must be unique.
    • The name cannot contain special characters "/[]:|<>+=;?*@ and control characters, cannot start with a space, and cannot end with a space or a period (.).
    • The name can contain case-insensitive letters. For example, aa and AA cannot be created at the same time.
    • The user group name cannot be the same as the name of a local authentication user.
    • The name contains 1 to 256 characters.

    Description

    Description of the local authentication user group.

    [Value range]

    The description can be left blank or contain up to 255 characters.

    The newly created local authentication user group is a common user group. When members in the user group access a shared file system of the storage system, they can have the corresponding permissions only after being authenticated.

  5. In the Privileges area, select desired privileges for the local authentication user group. You can view the function description of a privilege in the Description column.
  6. Click OK.