Inside Windows 98

Previous chapterNext chapterContents


- 26 -

Peer Resource Sharing and Security


As a peer-to-peer network operating system, Windows 98 enables you to share resources such as disks and printers on your PC with other users on the network. Windows 98 can serve as your entire network operating system, or it can function in concert with another network operating system, such as Novell NetWare. Even if you use another network operating system, however, you still can take advantage of the peer-to-peer networking in Windows 98.

This chapter explains how to share resources in Windows 98, as well as how to access and use shared resources across the network. The chapter covers the following topics:

Sharing and Using Disk Resources

One of the primary functions of any network is to enable users to share folders and files. Windows 98 enables you not only to access folders and files on a network file server but also to share your local disks and access disks shared by other Windows 98 users. This section explains how to share your local disk resources and how to access disk resources shared by other users.

Setting Up for Sharing

Before you can share your resources with other users, you must enable resource sharing on your computer. To do so, open the Control Panel and choose the Network object. From the Configuration property page, choose the File and Print Sharing button to open the File and Print Sharing dialog box shown in Figure 26.1.

FIGURE 26.1 The File and Print Sharing dialog box.

The check boxes on the File and Print Sharing dialog box enable you to control whether you can share your local resources with other users. Enable the check boxes as appropriate for your situation.

Sharing Disks, Folders, and CDs

You can use Windows 98 to share an entire disk (hard disk or floppy disk), one or more directories, or a CD. If you have used Windows for Workgroups, you're familiar with the process; the primary difference is that Windows 98 makes it much easier. Rather than use the File Manager to share a disk resource like you would in Windows for Workgroups, you can share the resource from My Computer, Explorer, or any folder window.

To share an entire disk, simply share its root directory. Open My Computer and right-click on the icon of the disk you want to share to display its context menu. Choose Sharing to open the Sharing property page for the disk as shown in Figure 26.2.

FIGURE 26.2 The Sharing property page.


TIP: You can share a disk from Explorer. Select the disk, and choose File, Properties, or press Alt+Enter to display its property sheet (including the Sharing page). If the property sheet doesn't include a Sharing page, your computer is not configured for sharing. Use the Network object in the Control Panel to enable sharing on your computer.

Choose the Shared As option button to enable the sharing controls on the property page. In the Share Name text box, enter the name by which you want the resource shared. By default, Windows 98 suggests the drive's logical ID, such as C or D, as the share name. You can accept the default name or enter your own. For example, you might share the disk using a name such as Applications. Another user browsing the network for resources sees a folder named Applications on the computer sharing the disk. Opening the Applications folder displays icons for all of the directories on the shared disk.


TIP: Share names can be up to 12 characters long and can contain letters, numbers, and the following characters:

! # $ % & ( ) - . @ ^ _ ` { } ~

You should choose a share name that makes sense to users who browse the network. Whereas the name QR2RPTS might make sense to you, Reports_2ndQ might make more sense to others.


You also can enter an optional comment string in the Comment text box. If a user browses from a Windows NT or Windows for Workgroups node, the comment appears next to the resource name in the user's Browse dialog box. If the user browses from a Windows 98 node, the comment appears in the property page for the resource (which only appears if the user selects the resource's icon, then displays its properties). The comment also appears in folder windows and other Windows 98 browse-related objects (such as common File Open and Save dialog boxes) if these objects are configured to show a detailed list rather than icons or a simple list.

Controlling Access

Also on the Sharing property page is a group of controls that enables you to specify share-level access rights and passwords for the shared resource. You can configure to share the resource as read-only, which enables other users to read but not modify the objects in the share. Or you can grant full access to the resource, which enables other users to read and modify the objects in the share. If you prefer, you can parcel out access based on the user-supplied password, enabling some users to gain read-only access and others full access to the resource. To grant full or read-only access based on password, choose the Depends on Password option button. A user who supplies the read-only password gets read-only access to the share; a user who supplies the full access password gets full access to the share.


WARNING: If you share an entire disk (by sharing its root directory) and grant full access to the share, other users can modify every file and directory on the disk. You should, therefore, use some form of password protection.

After you specify the access method by which you want to share the resource, enter a password in the appropriate text box. Choosing Depends on Password as the access method enables both the Read-Only Password and Full Access Password text boxes. Enter different passwords in each one and choose OK to begin sharing the resource.


TIP: You can create a hidden share that does not show up in browse lists or the share window of the computer that shares the resource. Refer to the section "Creating a Hidden Share" later in this chapter to learn how to create hidden shares. To learn how to share resources on a user basis rather than share basis, see "Using Pass-Through Security" later in this chapter.

Sharing One or More Directories

In general, you probably don't want to share an entire disk. Sharing individual directories enables you to share part of your disk and prevent access to the rest. When you share a directory under Windows 98, however, any subdirectories in the shared directory also are shared. Unlike Windows NT, NetWare, and other network operating systems, Windows 95 does not enable you to control access to subdirectories separate from a shared parent directory.

To share a directory rather than an entire disk, open Explorer or a folder window to the directory's parent. Select the icon of the directory you want to share and display its property sheet. Use the Sharing property page to share the directory as explained previously.

Sharing a Floppy Disk

You can share a floppy disk just as you can any other disk. You do so the same way you share a hard disk, except you can easily remove the floppy disk, whereas you can't so easily remove most hard disks.

Sharing a CD

You can share CD-ROMs in the same manner you share hard disks, including sharing only a selection of directories on the CD if necessary. The 32-bit CD file system in Windows 98 enables sharing CDs without any special configuration. Generally, all you have to do to share the CD is open My Computer or Explorer, select the CD's drive letter, and use its Sharing property page to share the CD. Because CD-ROMs are read-only devices, users can't gain full access to the CD. They can, however, read the CD. If necessary, you can password-protect the CD just as you can any other shared resource.


TIP: Normally, you don't need to use Mscdex in Windows 98 to access a CD-ROM drive on your system. Mscdex is the real-mode CD-ROM driver supplied with DOS. If Windows 98 does not support your CD-ROM drive's host adapter, however, you might have to use Mscdex to access your CD-ROM drive. If so, add the /S switch to the end of the Mscdex command line in your AUTOEXEC.BAT file to enable Mscdex to support CD-ROM sharing.

Creating a Hidden Share

Sometimes it's useful to create hidden shares, which do not appear in the browse list or folder windows when users browse your computer for shared resources. To access a hidden share, the user must specify the hidden share name directly in a UNC path or when mapping one of the local drive IDs to the hidden share (see Figure 26.3). This means that the user must know not only the password for the hidden share, but also its name, which the user has no means of determining on his own.

FIGURE 26.3 Connecting to a hidden share.

To create a hidden share, just add a dollar sign ($) character to the end of the share name. To share drive C as a hidden share, for example, you could use the share name "C$." Or you could use any other valid share name that ends with the $ character.

Using a Shared Disk Resource

Some of the most useful and welcome changes in Windows 98 are those in the presentation of network resources. These changes make it extremely simple for you to access shared network resources and eliminate the need to map local drive IDs to remote network resources to use. The keys to these improvements are the Network Neighborhood and Universal Naming Convention (UNC) path names.

The Network Neighborhood is a typical folder you open to display icons for each of the computers in your workgroup. Selecting a computer's icon from the Network Neighborhood displays all the resources that computer shares, including disks, printers, and Microsoft Fax directories (used for sharing a fax modem, as explained in Chapter 29, "System Policies and User Profiles").

If a shared resource is not password-protected or your password cache already contains the correct password for the resource, you can begin using it just as you do local disks, folders, and files. If you double-click a shared folder icon, for example, Windows 98 opens a folder window showing the contents of the folder, including its files and other folders. You can open a network folder and start an application by double-clicking its icon, or you can open a document file the same way. If you want to copy files from the remote computer to your own, you simply select the files and drag them to a local folder or to your desktop.

You also can work with the Network Neighborhood in Windows 98 applications' File Open dialog boxes. This common Open dialog box (see Figure 26.4) works much like a mini-Explorer window, enabling you to open the Network Neighborhood like a local folder, drilling down through its objects until you locate the file you want to open. The Save and Save As dialog boxes also work in the same way. By enabling you to open a remote network computer's shared resources as if they were stored in a local folder, Windows 95 eliminates the need for mapping those resources to a local drive ID.

FIGURE 26.4 The Network Neighborhood in a typical Open dialog box.

You also can use UNC path names to access remote shared folders and files. A UNC path name consists of the name of the computer sharing the resource, the resource's share name, and optionally, a filename. To open the file named THIRD QUARTER REPORT.DOC in a shared folder named QtrReports on a server named Sales, for example, you would enter \\Sales\QtrReports\ Third Quarter Report.Doc in the Open dialog box. Being able to access folders and files in this way enables you to navigate very quickly to shared network resources.


TIP: One very useful tool is the capability to create folders from within the Save and Save As (and Open) dialog boxes. If you want to create a new folder on a local or remote disk, you can simply right-click in the folder/file list in the dialog box and choose New | Folder. After you create the folder, you can rename it if necessary and then select files to store in it without leaving the dialog box.

Browsing on Microsoft Networks

If you use the Client for Microsoft Networks, your primary mechanism for browsing the network is the Network Neighborhood. When you browse the network, you see the following types of computers in the Network Neighborhood (and Entire Network):


NOTE: If your network contains NetWare servers and you also run the Client for NetWare Networks, NetWare servers and computers running the File and Printer Sharing for NetWare Networks service also appear in your Entire Network folder. Note, however, that you can't run the File and Printer Sharing for NetWare Networks and the File and Printer Sharing for Microsoft Networks services on the same computer. You can, however, use both the Microsoft and NetWare clients to access Microsoft- and NetWare-based servers.

To provide a structure to the browse mechanism, Microsoft networks such as Windows 98 employ master browse servers. The master browse server maintains the master list of computers in a workgroup, domains, and workgroups, with one master browse server for each protocol used. Backup browse servers also serve to offload some of the overhead. Generally, there is one master browse server for every 15 computers in the workgroup. When you open the Network Neighborhood, your computer communicates with the browse server(s) to obtain a list of computers, workgroups, and domains.

The master browse server is assigned automatically by the network. When a computer first starts up, it checks the workgroup to determine if a browse server is available. If one is not available, a master browse server is elected. The master browse server then designates backup browse servers as necessary.

Although designation of master and backup browse servers usually happens automatically, you can control whether your computer can become a browse server. Typically, the only reason to change the browse server status of your computer would be to control network performance. If your computer is slow or has little available RAM, you should exclude it from acting as a browse server. If your computer is one of the faster ones on the network and has plenty of RAM available, consider allocating it as the master browse server.

To control browse services for your computer, open the Network object in Control Panel, choose File and printer sharing for Microsoft Networks, and then choose Properties. The Advanced property page appears, as shown in Figure 26.5.

FIGURE 26.5 Use the Advanced property page to control browsing.

The Property list in the Advanced property page contains two settings:


NOTE: At least one computer in each workgroup must use a setting of Automatic or Enabled for browsing to function normally. Windows 98 does not designate computers connected to the network by a RAS connection as browse servers.

Adding and Removing Computers from the Browse List

When a PC starts Windows 98, the computer announces itself to the master browse server for its workgroup. The master browse server notifies the backup browse servers that an updated list is available, and the backup browse servers then request an update as network traffic and their own CPU load allows. For this reason, a computer appearing in a workgroup browse list can take as long as 15 minutes, although the time is generally much shorter unless the workgroup has considerable network traffic or numerous computers. Even though a computer doesn't appear in the workgroup, users can connect to it through UNC path names or previously configured persistent connections.

When you shut down computers in a workgroup, their names eventually disappear from the browse list. If you shut down the computer normally (choose Start, Shut Down), the computer announces to the browse master that it is shutting down. The browse master updates its browse list and advertises to the backup browse servers that an update is available. Again, it can take time for a computer to be removed from all browse lists. If the computer hangs or shuts down improperly for some reason, it doesn't have an opportunity to announce its shutdown. For this reason, the computer might continue to show up in the browse list until its name entry "times out," which can be as long as 45 minutes.

Browsing on TCP/IP Subnetworks

The browsing mechanism in Windows 98 supports browsing on TCP/IP subnetworks. To enable browsing for TCP/IP, the network must include a WINS server (such as provided by Windows NT), or the Lmhosts file(s) must include #DOM entries. #DOM is a special keyword used in Lmhosts to control how browse and logon services function in a TCP/IP network. For information on configuring browsing and setting up Hosts and Lmhosts files, refer to Chapter 22, "Configuring Internet Connections."

LAN Manager Compatibility in Other Networks

Some third-party network operating systems are compatible with Microsoft LAN Manager. These network operating systems include IBM LAN Server and Microsoft LAN Manager for UNIX. On these network operating systems, resources on Windows 98, Windows for Workgroups, and Windows NT computers appear in the browse list.


NOTE: As with Windows 98, Windows 95, Windows NT, and Windows for Workgroups, you can use the Windows 98 GUI interface (Network Neighborhood) or the NET VIEW command from a command prompt to browse for resources on LAN Manager-compatible networks.

Other LAN Manager-based networks, such as DEC PATHWORKS, and Microsoft-compatible networks, such as AT&T StarLAN, do not support browsing. You can, however, connect to resources on these networks using their normal connection interfaces.

Mapping Drives to Remote Resources

Although you can easily use disk resources through UNC path names without associating (mapping) local drive IDs with those resources, you still can map those drive letters if necessary. If you have a Windows 3.x program that doesn't support UNC path names, for example, mapping to the remote resource offers the only means of accessing the resource from that program. Or your computer might require specific mappings to remote drives for configuring a mail server, file server, or other reason.

Generally, you can map drive letters through any folder window for the resource, such as Network Neighborhood, Explorer, or Entire Network. To map a local drive letter to a remote disk resource, display the folder that contains the resource, select the object to which you want to connect, and open its context menu. From the context menu, choose Map Network Drive. If you prefer not to use the context menu, choose File | Map Network Drive, or click on the Map Network Drive button in the toolbar, which opens a Map Network Drive dialog box.

To map a local drive ID to a remote resource, select the drive ID you want to use from the Drive drop-down list, then enter the path to the server in the Path combo box. You can select the drop-down button to select from previously used connections or type a new path name. You can specify a UNC path name or a NetWare-style path name (such as SERVER/SYS).

If you want the drive association to last only as long as your current Windows 98 session, clear the Reconnect at logon check box. If you want the connection to persist so that it reconnects for each of your Windows 95 sessions, enable this check box. The connection to the resource uses the same drive letter in each Windows 98 session.


NOTE: Persistent connections are not permanent. You can disconnect a network resource, which prevents it from being mapped on subsequent Windows 98 sessions.

If you associate a local drive ID with a directory on a NetWare server, the Map Network Drive dialog box contains an additional check box, the Connect as root of the drive check box. You enable this check box to map the selected directory as the root directory of the selected drive. This corresponds to the NetWare MAP ROOT command.

Creating Shortcuts to Remote Resources

Although the Network Neighborhood makes browsing for resources easy, drilling down through a list of workgroups, servers, and resources to find a resource you use often can prove time-consuming. A great solution is to create a shortcut to the resource, in a folder you create or on your desktop. You can then access the resource simply by double-clicking its shortcut icon.

You create a shortcut to a remote resource in the same way you create shortcuts to local objects. Open the Network Neighborhood folder and locate the object to which you want to create a shortcut. Right-drag the resource's icon to the desktop and choose Create Shortcut(s) Here. When you double-click the shortcut icon, Windows 98 determines whether the password for the resource is stored in your password cache. If so, Windows 98 opens a folder on the desktop for the resource. If not, Windows 98 prompts you for the correct password.

Using Pass-Through Security

In addition to allowing you to use share-level security to protect shared resources, Windows 98 also enables you to use pass-through security, also referred to as user-level security. Rather than validate user access based solely on the passwords assigned to the shared resource, pass-through security relies on user validation by a security server such as Windows NT or NetWare servers. If you run the File and Printer Sharing for Microsoft Networks service, you must specify the name of a Windows NT domain or Windows NT workstation as your security server. If you run the File and Printer Sharing for NetWare Networks service, the security server must be a NetWare server or NetWare 4.x server running bindery emulation.

Here is how pass-through security works: A user attempts to connect to a shared resource on your computer. Windows 98 sends a message to the security server asking for verification of the user's right to access the resource. The security server validates the user's account and password, and if both are valid, sends confirmation of the user to your computer. Your computer then grants access to the resource based on the rights assigned to the user.


TIP: You can't use share-level security if you use only the File and Printer Sharing for NetWare Networks service; in that case, you must use pass-through security or use a Microsoft network client and sharing service.

The list of users who can access the resource and their access levels is stored on your computer. The user accounts and passwords, however, are stored on the security server. You can add user accounts and passwords to the security server only by running the account management utility the server provides (such as User Manager on Windows NT, or SYSCON or NETADMIN on NetWare), but you can run these utilities from your Windows 98 workstation if you have sufficient access rights on the server and access to the management utility. Regardless of your security level on the server, you can add names to the share list for resources you share on your PC. The following section explains how to share a resource with user-level security.

Sharing Resources with User-Level Security

To employ user-level security on your computer, you first must enable user-level security through the Control Panel. Open the Network object in the Control Panel and click the Access Control tab to open the Access Control property page shown in Figure 26.6.

On the Access Control property page, choose the User-level access control option button. In the Obtain list text box, type the name of a Windows NT domain, a Windows NT workstation, or NetWare server that you want to act as security server. Choose OK, and Windows 98 prompts you to restart the computer to make the change take effect.


NOTE: Any directories your computer currently shares are removed from sharing when you enable user-level security. You must reshare the directories after Windows 98 restarts. Also, Windows 98 doesn't support the use of NetWare domains or NetWare Name Service to support user-level security, although it does support NetWare 4.x with bindery emulation.

After you configure your computer for user-level security and restart Windows 98, you can share directories with user-level access. To do so, open a folder or Explorer window that contains the folder you want to share or choose a disk you want to share and then open the object's context menu. Choose Sharing to display the Sharing property page shown in Figure 26.7. Notice that this Sharing property page differs from the Sharing page you see during share-level access.

FIGURE 26.6 The Access Control property page.

FIGURE 26.7 The Sharing property page with user-level security enabled.

Choose the Shared As option button and enter the share name and optional comment in the Share Name and Comment text boxes. You must then add account names to the list of users who can access the shared resource. To do so, choose the Add button to open the Add Users dialog box, which shows the Add Users dialog box you see if you use a Windows NT domain for security services.

You can assign read-only, full, or custom access to the shared directory. To assign an access type to a user or group of users, select the user or group name from the list and choose the Read-Only, Full Access, or Custom buttons. Windows 98 adds the selected names to their respective groups. After you add all the groups or users to whom you need to give access to the directory, choose OK. If you have specified Custom for any of the users or groups, the Change Access Rights dialog box appears.


TIP: If you use the Custom button to add multiple user or group names, all those groups and users share the same custom access rights (explained next). If you want to assign different custom rights to specific users or groups, choose OK to add the current selection of users and then choose the Add button to select other users and assign a different set of custom access rights. After you assign rights to a selection of users, groups, or both, you can edit individual group or user access rights without affecting the rights of any other users or groups you might have added at the same time as the one you're editing.

Unlike share-level security, which enables you to share a directory only as read-only or full access, user-level security enables you to apply a fine degree of control over the types of access users and groups have to your shared resources. The check boxes in the Change Access Rights dialog box enable you to specify one or more access rights for each user to whom you assign custom access rights. Table 26.1 lists common file operations and the access rights required to enable those operations.

TABLE 26.1 User Level File Operations and Access Rights

File Operation Access Rights Required
Change access rights Change access control
Change directory or file Change file attributes attributes
Copy files from a directory Read, list files
Copy files to a directory Write, create, list files
Create and write to a file Create files
Delete a file Delete files
Make a new directory Create files
Read from a closed file Read files
Remove a directory Delete files
Rename a file or directory Change file attributes
Run an executable file Read, list files
Search a directory for files List files
See a filename List files
Write to a closed file Write, create, delete, change file attributes

Enable or clear the appropriate check boxes to assign the necessary access rights to the selected users and groups and choose OK to apply the access rights. After you apply access rights, the Sharing property page lists the users and groups and their respective rights.

To edit a user's or group's access rights, select the user or group from the Sharing property page and choose Edit. To remove a user or group from the access list, select the user or group and choose Remove.


TIP: Windows NT and NetWare both enable you to set access rights on individual files on the server. Because Windows 95 relies on the FAT file system, you can't assign access rights to individual files--you can assign access rights only at the directory level. Access rights for a shared directory also pass down to its subdirectories.

Configuring Security under NetWare

User accounts, groups, passwords, and access rights are stored under NetWare 3.x on a NetWare server in a database called the bindery. NetWare 4.x uses bindery emulation to make it appear that each NetWare server contains a bindery. Each server contains a separate bindery.

If you use more than one NetWare server in your network environment, you might experience problems with user-level security because your Windows 95 workstation can use only one server as the security server. The solution is to add all user accounts and related information to one NetWare server on the network, and then use this server as the security server for all user-level access security by all Windows 95 workstations on the network.

Sharing and Using Printer Resources

Windows 98 enables you to share printers with other users on the network in much the same way you share disks and directories. Shared printers appear in a remote computer's folder when you access the folder through the Network Neighborhood or Entire Network folders. Unlike Windows for Workgroups and other network operating environments, you don't have to map a local printer port to a remote printer before you can print it; you can simply use the printer's UNC path name to print. Or you can associate a remote printer with a local printer port if you need to support printing from DOS and Windows 3.x applications.

Sharing a Local Printer

The Sharing page of a printer's property sheet enables you to share the printer with other users on the network. To share a printer, first configure all its other settings and print a test page to verify that the printer works properly. Next, display the Sharing page of the printer's property sheet. Choose the Shared As option button to enable sharing and enter a name for the printer in the Share Name text box; this is the name that other users see when they browse the network for resources. You also can add an optional comment in the Comment text box. This comment appears as additional information in the Network Neighborhood folder if the user configures the folder for a detailed view.


TIP: To password-protect the printer to restrict its use, enter a password in the Password text box. Users are to enter the password when they attempt to access the printer. Note that the Password text box appears on the property page only if you are employing share-level security.

Printers offer no varying levels of access rights--a user either can or cannot print to a printer. If you use share-level security, you can specify a single password in the printer's Sharing property page to protect access to the printer. If you use user-level access, you can add groups and users to the access list for the printer, assigning full access to each. Applying user-level security and configuring the user list is nearly the same for printers as for disks. Simply open the printer's Sharing property page and use the same methods described in the section "Sharing Resources with User-Level Security" earlier in this chapter.

Chapter 8, "Printing and Managing Printers," explains how to install a network printer so you can access it across the network. For help capturing a local printer port and associating the port with a remote network printer, refer to Chapter 8's section "Capturing and Releasing Ports."


Previous chapterNext chapterContents

© Copyright, Macmillan Computer Publishing. All rights reserved.