[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Groups in the alternative user solution


> Seems unlikely to me, given the difference between DAC and MAC.
> But I'm open to other opinions on the subject.

What about Casey's suggestion in this thread:

> 
>     root:*:sysadm
>     fred:wheel:wand
>     *:wheel:staff
>     *:*:normal
> 
> Fred would be in "wand" if only in group wheel,
> in "normal" if in groups wheel and dev. Fun.

Not sure I understand... 
So if Fred is in more groups other than wheel, 
he maps to normal? What's the rationale for that?
Controlling information disclosure? Does that * 
take precedence to fred? What about conflicts? 
This seems complicated..

============

Should this idea be dropped? More opinions?




--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with
the words "unsubscribe selinux" without quotes as the message.


This mailing list archive is a service of Copilot Consulting.