Contribute permissions vs. network permissions

Ask a Question related to Macromedia Contribute Connection Administrtion, Design and Development.

  1. #1

    Default Contribute permissions vs. network permissions

    We are currently implementing Contribute in a website that is highly
    centralized, with approximately 50 department-level CT writers and 4 CT
    administrators. We thought we had developed a workable deployment scheme, but
    are now seeing that the Contribute architecture apparently does not provide the
    degree of security we had anticipated.

    We have created roles that mirror our organizational and web directory
    structure, and populated those roles with writers via connection keys. We have
    configured network read/write permissions for our writers in the MMWIP, _mm,
    _notes and _bak folders.

    After some embarrassing initial trainings, we discovered that we also need to
    configure read/write permissions in both the web root and the specific
    departmental subdirectories. Suddenly, we find ourselves expanding permissions
    on the web server instead of constricting them as we had anticipated. We're
    dumbfounded to discover that our content management system requires us to open
    the door to rogue editing with Dreamweaver, Frontpage, even Notepad.

    We are desparate for suggestions as to how others have addressed this
    situation. Below is some relevant info on our deployment. Many thanks to anyone
    who can share advice or experiences.

    Contribute version: 3.1
    Web server: IIS 5
    Connection type: LAN

    _______________________
    Greg Hope
    MiraCosta College
    One Barnard Drive
    Oceanside, CA 92056
    E: ghope at miracosta dot edu
    T: 760.795.6763
    F: 760.795.6723

    ghope Guest

  2. Similar Questions and Discussions

    1. Permissions over the network
      I am a novice when it comes to managing 2003 Server, IIS, Websites, Contribute and CPS. Windows Server 2003 in a domain, all else working properly...
    2. network unavailable or permissions
      I setup my first user on Contribute today. It's been quite a ride, but I think I have everything setup finally. I have ldap enabled, and I know it...
    3. Network permissions vs. Contribute permission groups
      Our web files are stored on a Netware server. I want a particular group of users to be able to edit one subdirectory in the web-site, but not the...
    4. How do I set permissions for network computers?
      I am the administrator on my computer and I can't figure out how to set permissions for my other computer that is on my network. When I get to the...
    5. cant change file permissions from read only on network
      Im on WindowsXP Home--I have a network setup and experience no problems, except for one. I can share drives on each computer and see all the data,...
  3. #2

    Default Re: Contribute permissions vs. network permissions

    ghope wrote:
    > We are currently implementing Contribute in a website that is highly
    > centralized, with approximately 50 department-level CT writers and 4 CT
    > administrators. We thought we had developed a workable deployment scheme, but
    > are now seeing that the Contribute architecture apparently does not provide the
    > degree of security we had anticipated.
    >
    > We have created roles that mirror our organizational and web directory
    > structure, and populated those roles with writers via connection keys. We have
    > configured network read/write permissions for our writers in the MMWIP, _mm,
    > _notes and _bak folders.
    >
    > After some embarrassing initial trainings, we discovered that we also need to
    > configure read/write permissions in both the web root and the specific
    > departmental subdirectories. Suddenly, we find ourselves expanding permissions
    > on the web server instead of constricting them as we had anticipated. We're
    > dumbfounded to discover that our content management system requires us to open
    > the door to rogue editing with Dreamweaver, Frontpage, even Notepad.
    >
    > We are desparate for suggestions as to how others have addressed this
    > situation. Below is some relevant info on our deployment. Many thanks to anyone
    > who can share advice or experiences.
    >
    > Contribute version: 3.1
    > Web server: IIS 5
    > Connection type: LAN
    >
    > _______________________
    > Greg Hope
    > MiraCosta College
    > One Barnard Drive
    > Oceanside, CA 92056
    > E: ghope at miracosta dot edu
    > T: 760.795.6763
    > F: 760.795.6723
    >
    > From - Fri
    We are looking for the same answer. We are just starting to administer
    Contribute 3.11 (with contribute publishing server) at a school, looking
    at around 10 users now. We would like to avoid having to give a group
    access to everything on our server, and would also like to know some
    best practices on ftp access for users. Any suggestions would be
    appreciated.

    Matt Adams
    District Network Specialist
    Winnebago Schools
    Matt Adams Guest

  4. #3

    Default Re: Contribute permissions vs. network permissions

    We did get our Contribute system up and running, and have had only a few
    hiccups since then. Here are a few details. We're using sFTP, but the same
    details apply if you are using FTP. We are using Active Directory, hence the
    "AD" below.

    Configure end user permissions on web server:
    1. Revoke all active directory permissions for end users, except read and
    browse.
    2. Grant end users read/write/modify/delete permissions on the following
    directories: _mm, _bak, _notes.

    Create an administrative AD user that will be used by Contribute only:
    3. Create an Contribute user with full active directory permissions for the
    entire web site.
    *** We used long, randomized strings for both the username and password for
    this account. The only time you will need to enter these is when you are
    creating an administrator connection for yourself or other admins. It's a pain,
    but worth the inconvenience.
    4. Give the Contribute user FTP permission.

    Create the administrator connection in Contribute:
    5. Create a new connection in Contribute using the administrator role.
    6. Set the connection method as either FTP or sFTP.
    7. The FTP (or sFTP) username and password will be those of the Contribute
    user created in step 3.

    Send connection keys to end users:
    8. When using the Connection Key Wizard, select Yes to send your current
    connection settings, and check the box to Include my FTP username and password.
    *** Connection keys are encrypted, so it is safe to be passing this
    username/password via this method.
    9. Select the appropriate role, then finish.
    10. Address the email to the desired users and send.

    We created clones of the Writer role that to match our major subdirectories.
    For example, we have a folder at the root named "StudentServices" and therefore
    a role with that name. We could have created more granular roles that grant
    editing permission at a lower level, but instead opted for fewer roles and to
    simply monitor incoming drafts to confirm who they're coming from. This makes
    it easier for our end users to share the work load.

    Also, we have only four users with publishing permission in Contribute.
    Everyone submits their drafts for publication. You may opt for department-level
    publishers to reduce the load on your admins.

    Hope this helps!

    ghope Guest

Posting Permissions

  • You may not post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139