How to Grant FTP Folder Permissions to Active Directory Users
Standard FTP doesn't allow you to change permissions or ownership of files, but for FTP servers it is enough to distribute such things via custom SITE commands. At least this is common for FTP servers hosted on UNIX.
Try connecting to a server with a standard FTP client and enter site help
. This should give you a list of the available SITE commands. Then you can get usage for a specific command by typing site help <cmd>
.
I'm not sure if your options would be against a Windows based server as the permissions model is more granular than standard UNIX permissions. On a UNIX server, you can often change group ownership and permissions, but changing the owner of a file is prohibited unless you are root. I didn't need to be told that logging into an FTP server as root is a really bad idea.
Hope it helps you.
R
a source to share
You are not saying which FTP server you are using or how you want the AD user to interact with the new folder. I am assuming you are using the IIS FTP service and need your AD users to be able to use FTP to access the new folder.
IIS uses the same permissions as other file access methods in Windows (accessed through the Security tab in the Folder Options view).
I created a WinForm that would do the following: create a new local user account (and add it to a group), create a new directory in our FTP server base directory, create a new virtual FTP folder (so that the user can map a folder connection) and finally, give the new user full control over the new directory (and since the directory was a virtual folder, the new user has full control over FTP).
It looks like you don't need to create a new user, you just need to give them permission to make changes to the new directory. In my application, I lay out to call a batch file and pass some parameters to it.
Command to change access rights to a directory (or file):
cacls [The path to your new directory] /E /P [The AD user name]:C
I don't remember what these parameters mean; I suggest you examine the command to make sure it does exactly what you want it to do.
To accomplish this with VB.Net:
Shell(System.Configuration.ConfigurationSettings.AppSettings.Item("CACLS_batPath") & " " & strFolderPath & " " & _strUserName, AppWinStyle.NormalFocus, True, -1)
This will open a visible command window and execute the batch file passing parameters to it. (I just thought I was doing this in WinForms, and it might not be that easy to call from ASP.Net, see here for information on executing a batch file from ASP.Net: http://codebetter.com/blogs/brendan. tompkins / archive / 2004/05/13 / 13484.aspx )
BAT file content:
echo "update file permissions"
cacls %1 /E /P %2:C
REM PAUSE
Good luck!
a source to share
I am assuming you are creating a folder and want to set permissions in a C # application.
You want to look at the DirectorySecurity class ( msdn )
You create a directorySecurity class for the newly created directory, and then add FileSystemAccessRules to define appropriate access based on AD users and groups.
a source to share