> Ok, I'm working on a dev server with the following structure:
>  
> D:\ is the partition with the data on it. Under D:\ there are
> the SQL database files as well as other miscellaneous stuff
> that the average person doesn't need to deal with. Then there's
> a "websites" directory. Basically, management wants to lock it
> down so that when developers RDS in, they can only see the
> websites directory. I know that with dreamweaver you could tell
> everyone to put D:\websites as their root RDS folder in the client
> setup, but that's not really secure.
>  
> What I was wondering is if I set up the RDS service to run as a
> user account that didn't have access to the root D:\ but it did
> have access to the websites folder, what would happen? Would that
> fix everything? Would it work if someone had D:\ in their
> Dreamweaver RDS configuration or would they have to change it to
> D:\websites? I wish RDS was a little more robust with maybe some
> account creation, etc with permissions and folder assignments.  

RDS is not designed to be a secure protocol.

If you're running CFMX, there is no "RDS service", in the sense of a
separate process that can be run as a specific user. In CFMX, RDS is run by
the CF service.

You can limit the rights of the CF service (or the RDS service in CF 5 or
earlier, I suppose) so that it doesn't have rights to change files within
various directories, but I suspect that you'll need to allow RDS the right
to traverse directories and list files at all levels from the
drive/partition root to the files you want to allow editing against. So, RDS
users would be able to see the D drive, but wouldn't be able to change files
in the drive root.

Dave Watts, CTO, Fig Leaf Software
http://www.figleaf.com/
phone: 202-797-5496
fax: 202-797-5444
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings]

Reply via email to