Specifications
Chapter 1 Overview of File Services 27
Using SACLs allows you to add another layer of access control on top of standard and
ACL permissions. Only users and groups listed in a SACL have access to its
corresponding service. For example, if you want to prevent users from accessing a
server’s AFP share points, including home directories, just remove the users from the
AFP service’s SACL. See “Setting SACL Permissions” on page 51 for instructions on how
to restrict access to file services using SACLs.
Customizing the Mac OS X Network Globe
The Network globe you find at the top level of a Mac OS X Finder window contains
shared network resources. You can customize the contents of the Network globe to suit
your clients by setting up automatically mounting share points. You can provide
automatic access to system resources such as fonts and preferences by automatically
mounting share points containing them in specific directory locations.
Share Points in the Network Globe
The Network globe on Mac OS X clients represents the /Network directory. By default,
the Network globe contains at least these folders:
• Applications
• Library
• Servers
You can mount share points into any of these folders. See “Automatically Mounting
Share Points for Clients” on page 40 for instructions.
Additional servers and shared items are added as they are discovered on your network.
Adding System Resources to the Network Library Folder
The Library folder in the Network globe is included in the system search path. This
gives you the ability to make available, over the network, any type of system resource
usually found in the local Library folder. These resources could include fonts,
application preferences, ColorSync profiles, desktop pictures, and so forth. You can use
this capability to customize your managed client environment.
For example, suppose you wish to have a specific set of fonts available to each user in a
given Open Directory domain. You would create a share point containing the desired
fonts and then set the share point to mount automatically as a shared library in
/Network/Library/Fonts on client machines. See “Automatically Mounting Share Points
for Clients” on page 40 for more information.
Security Considerations
Security of your data and your network is critical. The most effective method of
securing your network is to assign appropriate privileges for each file, folder, and share
point you create.