
by Paul Sanna and Larry Passo
Sharing is a critical part of almost any Windows-based network. Sharing in Windows networks means users can make resources on their computer available to other users. Without sharing, users are forced to copy files and folders to a network server volume if they want others to have access to them. In a more specific scenario, let's say that a coworker is working with a set of files related to a project, and those files are stored in a folder on the coworker's computer. Let's also say that you need to read and possibly edit one of those files. If the person shares the folder where the files are located, you can access any of the files in the folder from your desktop as if the files were stored on your own machine.
Users can also share other resources on their computer, such as printers. Let's say that a coworker has attached a color inkjet printer to her machine, and you have a color presentation you need to print. There is a better method than disconnecting the color inkjet and reattaching it to your computer. The coworker could share the printer, you could attach to it over the network, and then you could print to it as if it were directly attached to your computer.
Sharing is supported on both Windows and NetWare networks, but this chapter focuses primarily on sharing in a Windows network environment. A Windows network is one in which the computers operate on a peer-to-peer basis, and it usually consists of a mix of 16-bit Windows, Windows 95, Windows 98, and Windows NT computers.
Keep in mind that in a peer-to-peer network, any computer that provides resources to other computers is considered a server. Peer-to-peer networks usually have a relatively small number of computers--typically fewer than 10. A network with a dedicated server, which is usually known as a client/server network, is usually used to support networks with more than 10 computers.
Regardless of whether the Windows network is peer-to-peer or client/server, sharing works the same way. Sharing allows users to access such network resources as the following:
When any resource is made available over the network for users on other computers, that resource is known as a share. The term share will be used throughout this chapter. When a resource is shared, a hand appears under its icon on the screen (see Figure 43.1).
FIG. 43.1 A hand appears beneath the icon of any resource that is being shared.
NOTE: It's important for you to note that while shares allow files to be accessed from any computer that is connected to the network, only directories can actually be shared. When a directory is shared, all files and subdirectories it contains are available for network access.
Before you share any resource over the network, you need to decide what type of access control, or network security, your resources require. You have two choices for access control:
Share-Level Access Control
Share-level security is used to define a common level of security access to a specific share that applies to all users of that share. In share-level access, the user defines a share for a resource, gives it a name (such as "Project X Folder"), and optionally secures the share with a password. The user can also specify whether persons accessing the share can modify the contents of the shared directory or just read the files that are in the shared directory. Users can access the contents of a share, in this case a folder, simply by opening the folder. Naturally, if the share is secured by a password, the user would have to supply the correct password to access the contents of the share. The most important point to keep in mind with share-level access is that all users who know the password that protects the share will have the same type of access to the share.
User-Level Access Control
User-level access control allows access to be based on who a user is instead of whether he or she knows a password. This allows different users on the network to have individual, unique rights to each share. User-level security requires that a computer be able to maintain a secure, centralized account database and serve as a security validation server. NetWare Servers, Windows NT Servers, or Windows NT Workstations (in the absence of a Windows NT Server) can all function as security validation servers for Windows 98 computers. Windows NT domains can also act as external security validation agents.
NOTE: The process of using an external security validation server is referred to as pass-through validation.
The list of users and groups to which you can give access to your shared resources is maintained by your external security validation server. Any user with an account in the centralized account database can create shares on a Windows 98 system and assign security access to any user or group that has an account on the security validation server. Although you can add users to your own machine, you cannot use those user accounts on any other computer in the domain. Before you can give a user or group access to a share on your computer that is configured for user-level access, that user or group must have an account in the centralized account database on the security validation server.
TIP: Although the account must be created in the centralized account database, you can actually create the necessary account from Windows 98 if you have the proper software on your computer and administrative rights for the domain. Both Windows NT and Novell NetWare supply administrative utilities that allow remote network management from a Windows 98 computer. The Windows NT Server installation CD-ROM includes a copy of User Manager for Domains that can be run on a Windows 98 computer.
The two major differences between workgroups and Windows NT domains are their organizational structure and the number of users/computers they can support.
Each computer in a workgroup is responsible for its own administration and security. The various computers in a workgroup might consist of any combination of Windows 98/95, Windows for Workgroups, Windows NT Workstation, or Windows NT Member Server computers. Each user in a workgroup needs to have an account created for him or her on every computer in the network to which he or she needs access. The administrative overhead of creating and maintaining all the multiple user accounts in a workgroup usually limits their size to very small networks, typically fewer than 10 computers.
The central component of a Windows NT domain is a Windows NT Server that has been configured as a Primary Domain Controller (PDC). Every domain must have one PDC and can have one or more Windows NT Server(s) that have been configured as Backup Domain Controllers (BDCs). The PDC maintains a master list of all the valid user accounts in the domain. PDCs also replicate account information to their BDCs. Whenever a user logs on to a domain or requests access to domain resources, the domain's PDC or a BDC authenticates the request. Windows NT domains can be quite large, including up to several thousand users and computers.
NOTE: Windows 98 computers cannot join a domain. However, a user working at a Windows 98 computer can be authenticated by a domain controller during network logon and can gain access to domain resources.
Before user-level or share-level sharing is allowed in Windows 98, you must configure Windows 98 to allow sharing and to share other resources. Follow these steps to configure a Windows 98 machine to allow sharing:
FIG. 43.2 Add the file and printer sharing service.
FIG. 43.3 You can configure Windows 98 to share files and printers.
Share-level access is the least flexible of options, but it happens to be the easiest to administer. This section covers all the details.
The first step in creating shares with share-level security is to configure Windows 98 for share-level security. Follow these steps:
FIG. 43.4 You must define what type of access scheme you will use.
After you create a share, you must specify what type of access users will have to the resource. You can assign three types of access control to resources in a share-level network:
To create a share with share-level access, follow these steps:
TIP: You can create the share from wherever you can see the folder or drive, such as My Computer, the desktop, or Windows 98 Explorer.
FIG. 43.5 The Sharing tab enables you to define a share for a resource.
At some point, you might want to stop sharing a resource on the network. To remove a resource's share-level access, right-click on the resource that you want to stop sharing and choose Sharing from the menu that appears. Select the Sharing tab, choose the Not Shared option, and then click OK. The share will be removed.
CAUTION: Windows 98 will warn you if any network users are currently using a share when you try to remove it. You can then choose to either keep the share or remove it anyway.To prevent possible data loss, however, you should make sure that no users are using a share before you remove it.
Establishing shares with user-level access requires two steps:
When you allow users or groups access to a resource, you must specify what type of access to the resource they have. You assign one of three types of access to the resource:
Understanding Custom Access Rights
If you choose the Custom Access Rights option, you can custom-build an access type for a set of users or a group who has access to the resource. When you assign a user or group Custom Access Rights to a resource, you must define which of the following individual access rights the user has to the resource:
By switching these access rights on and off, you can create a very specialized mode of access to every resource you share. The set of access rights that you assign to a resource is referred to as its Access Control List (ACL).
CAUTION: If the ACL for a resource grants permissions to both a user and a group to which a user belongs, the user permissions will completely override the group permissions. This differs from Windows NT, in which user and group permissions are cumulative.
User-level security is not a default option in Windows 98, so you must explicitly configure Windows 98 to use user-level security by performing the following steps:
NOTE: As you learned earlier in this chapter, the external security provider can be a Novell NetWare Server, a Windows NT domain, or a Windows NT Workstation or Member Server.
CAUTION: If you are using a Windows NT domain for pass-through authentication, make sure that you enter the domain name--not the computer name--of the Primary Domain Controller or of a Backup Domain Controller.
NOTE: If you change the security context of your Windows 98 computer from share-level access to user-level access (or vice versa), you will have to re-create all the network shares on the system.
To create a share with user-level access control, follow these steps:
TIP: You can create the share from any place where you can see the folder or drive, such as My Computer, the desktop, or Windows 98 Explorer.
FIG. 43.6 You can give specific users rights to the resource you are sharing.
FIG. 43.7 User-level access control gives you access to the list of users from the security validation server.
CAUTION: Keep in mind that any access-level rights you provide to a group are granted to all users in that group. Before you grant access to a group, make sure you know the members of the group.
TIP: If you are using a Windows NT domain for your external security provider, you can use the Windows NT utility User Manager for Domains to determine the members of any group in a Windows NT domain. A version of the User Manager for Domains utility that will run on Windows 98 comes on the Windows NT Server installation CD-ROM.
If you are using a Windows NT Member Server or Windows NT Workstation for your external security provider, you need to run User Manager on that box to determine the members of a group.
NOTE: If you specify Custom Access Rights for more than one user or group, the rights you define in the dialog box at this point apply to each of those users and groups.
FIG. 43.8 If you choose Custom Access Rights, you can grant specific capabilities to certain users and groups.
FIG. 43.9 All of the users and groups you created access rights for are listed in the Properties dialog box for the resource you are sharing.
You can easily remove an individual user's or group's privileges to a resource you have been sharing with them. Note that this is different than removing a share for a resource, in which case all persons lose access to the resource.
To remove a user's or group's rights to a share, follow these steps:
FIG. 43.10 You can see which users and groups you have removed from the share.
Changing a user's or group's access rights is a simple task. To do so, right-click on the share you want to change, and choose Sharing from the shortcut menu. Click on the user or group in the Name list at the bottom of the dialog box, and then click Edit. The Change Access Rights dialog box appears (see Figure 43.8). Make any changes to the user's or group's rights, and then click OK.
So far in this chapter, you have learned about sharing folder and drive resources. Next, you will learn about the process for sharing other resources, such as printers and CD-ROM drives.
Sharing a printer is a fairly common task in small organizations. In typical workgroups, not everyone has a printer attached to his computer, but most persons have a printing requirement. In these cases, sharing a printer for the workgroup is the best way to provide everyone with printing capabilities.
To share a printer attached to your computer, you follow the same steps you learned earlier for sharing a file, folder, or drive option. Before you do that, though, you must take the following two steps:
In order to enable sharing of the printer, you have to access it from the Printers folder, which you reach by opening the Start menu and choosing Settings, Printers. Note that for user-level access rights, you can define only Full Access for each user or group to whom you provide access (see Figure 43.11). There is no concept of Read-Only or Custom rights when you're sharing a printer.
FIG. 43.11 You can grant only Full Access rights to a printer when you choose user-level access control.
Like sharing a hard drive, sharing a CD-ROM drive is one of the most common uses for sharing. Some users in organizations have not yet upgraded their computers to provide CD capability, but occasions arise when they must access data and programs that are stored on CD-ROM. In these cases, sharing a CD-ROM drive is the best way to solve the problem.
The process for sharing a CD-ROM drive is no different than that for sharing a folder or drive. Here are some tips to help with defining a share to a CD-ROM drive.
CAUTION: Keep in mind that CD-ROM drives are much slower than hard disks. If you anticipate that a number of users will simultaneously make use of the data on a shared CD-ROM, you should consider copying the data to a hard disk and then sharing the data from the hard disk.
You can also use a printer that another user has made available on the network and (presumably) provided you access rights for. The process for adding a network printer simply involves using the Add New Printer Wizard. When the wizard starts, make sure you specify that you are using a network computer. For more information on adding a printer to Windows 98, refer to Chapter 26, "Adding New Hardware."
© Copyright, Macmillan Computer Publishing. All rights reserved.