delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2010/03/15/10:55:30

X-Recipient: archive-cygwin AT delorie DOT com
X-Spam-Check-By: sourceware.org
Date: Mon, 15 Mar 2010 16:55:11 +0100
From: Corinna Vinschen <corinna-cygwin AT cygwin DOT com>
To: cygwin AT cygwin DOT com
Subject: Re: can not see mounted fs via ssh
Message-ID: <20100315155511.GR6505@calimero.vinschen.de>
Reply-To: cygwin AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
References: <alpine DOT LRH DOT 2 DOT 00 DOT 1003151014520 DOT 5590 AT rray2> <4B9E5404 DOT 3040506 AT cygwin DOT com>
MIME-Version: 1.0
In-Reply-To: <4B9E5404.3040506@cygwin.com>
User-Agent: Mutt/1.5.20 (2009-06-14)
Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Unsubscribe: <mailto:cygwin-unsubscribe-archive-cygwin=delorie DOT com AT cygwin DOT com>
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com

On Mar 15 11:36, Larry Hall (Cygwin) wrote:
> On 3/15/2010 11:26 AM, rray_1 AT comcast DOT net wrote:
> >what am i missing
> >i am sure you can see that i am very new to cygwin
> >where to find documentation on this is appreciated
> 
> Presuming that you're trying to use pubkey authentication, read the
> sections having to do with switching user context in the Users Guide:
> 
> <http://cygwin.com/cygwin-ug-net/ntsec.html#ntsec-setuid-overview>
> 
> See the 3 options for configuring the service to do this.  You need
> method 3.

There are other solutions, like calling `net use' in the ssh session.

But there's another important point here which also affects method 3.
If the machine is running Vista or later, and if the user is an admin
user, then the shares are usually attached to the non-elevated user
token.

However, the ssh session uses the elevated token (otherwise no admin
could do admin stuff in an ssh session).  This elevated user token
usually doesn't have the shares attached and the effect looks like it's
just not working, as before.  But it's still expected outcome since the
non-elevated and the elevated token have different logon session IDs.

Sigh, I think I should really add this to the documentation or the
FAQ at one point.  Windows authentication is very tricky somehow.


Corinna

-- 
Corinna Vinschen                  Please, send mails regarding Cygwin to
Cygwin Project Co-Leader          cygwin AT cygwin DOT com
Red Hat

--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019