[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Groups in the alternative user solution
> Seems unlikely to me, given the difference between DAC and MAC.
> But I'm open to other opinions on the subject.
What about Casey's suggestion in this thread:
>
> root:*:sysadm
> fred:wheel:wand
> *:wheel:staff
> *:*:normal
>
> Fred would be in "wand" if only in group wheel,
> in "normal" if in groups wheel and dev. Fun.
Not sure I understand...
So if Fred is in more groups other than wheel,
he maps to normal? What's the rationale for that?
Controlling information disclosure? Does that *
take precedence to fred? What about conflicts?
This seems complicated..
============
Should this idea be dropped? More opinions?
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with
the words "unsubscribe selinux" without quotes as the message.
This mailing list archive is a service of Copilot Consulting.