OMV User Homes clarification

  • Regardless of which file level permissions one creates the user home directory root folder, the actual user folders themselves are always created with rwx r-x r-x, the idea being that privileges and dynamic shares are used to control access for users to their respective homes. This also allows for a "administrator" group that, for example, can access everyone's home.


    However, from what I can tell this also means that any user can simply ssh into the box and have read access to everyone's home too. Is that correct? Why isn't this of any concern?


    I should note that this is also the behaviour on Synology (from where I am migrating), so it looks like standard operating practice. I just don't understand how it's acceptable - is the expectation to disable ssh for all users except root (I just checked and this seems to be the case)?


    A possibly related question: is there any reasonable situation when one would create a shared folder without the default 2775 permissions?

    • Offizieller Beitrag

    Is that correct? Why isn't this of any concern?

    Yep. Why would it be a concern? This is just what it defaults to. You can always change it. OMV is targeted at home users and these permissions aren't usually a problem.

    is the expectation to disable ssh for all users except root (I just checked and this seems to be the case)?

    ssh is disabled for all users unless you add them to the ssh group.



    is there any reasonable situation when one would create a shared folder without the default 2775 permissions?

    Yes. There are plenty of times I don't want a shared folder world readable and/or writeable.

    omv 7.0.5-1 sandworm | 64 bit | 6.8 proxmox kernel

    plugins :: omvextrasorg 7.0 | kvm 7.0.13 | compose 7.1.4 | k8s 7.1.0-3 | cputemp 7.0.1 | mergerfs 7.0.4


    omv-extras.org plugins source code and issue tracker - github - changelogs


    Please try ctrl-shift-R and read this before posting a question.

    Please put your OMV system details in your signature.
    Please don't PM for support... Too many PMs!

Jetzt mitmachen!

Sie haben noch kein Benutzerkonto auf unserer Seite? Registrieren Sie sich kostenlos und nehmen Sie an unserer Community teil!