[OpenAFS] pts membership

Chris McClimans openafs-info@mcclimans.net
Fri, 15 Aug 2003 14:17:41 -0500


Thanks Russ, this is exactly what I needed on the AFS side.

On the unix/windows side I may need to remove the general nss_switch 
based groups and try to make all applications respect the privacy 
concerns of group membership. Has anyone attempted anything similar 
with nss_* based solutions such as nss_ldap? Is it even possible? The 
other main applications are restricting access to login to specific 
boxes and mailing lists.

-chris

Russ Allbery <rra@standford.edu> writes:

Chris McClimans <openafs-info@mcclimans.net> writes:

  > Can any authenticated user list pts membership? In the US University
  > system we are all governed by FERPA and cannot release information 
(such
  > as class enrollment) unless the students specifically allow it.

  See <http://www.openafs.org/pages/doc/UserGuide/auusg008.htm#HDRWQ74>.
  It's controllable by the group privacy flags.