[OpenAFS] Questions about AFS security

Derrick J Brashear shadow@dementia.org
Sun, 20 Jan 2002 18:15:25 -0500 (EST)


Charles Clancy wrote:
> System:administrators can do all the vos, pts, and fs commands.  Members
> of 'bos listusers' can do bos stuff, like stop/restarting the server
> processes, and the 'bos exec' too.  People who have had 'kas setfields
> <user> -flags admin' can manage the kaserver (create users, etc), but
> you're not using that.

Not quite true. vos operations may use UserList (bos listuser) if they
involve manipulating ot quite true. In many cases vos operations use
UserList; You are, after all, manipulating the server's disk.

-D