[OpenAFS] PTS groups

Matthew Cocker matt@cs.auckland.ac.nz
Mon, 29 Nov 2004 15:39:21 +1300


Hi

I have been searching the web and have come up with a confused view of 
what a you can do with PTS groups. Up until now we have mostly used user 
based acls and a only a few PTS groups (say 20-30 small groups).

Now that our cell is being expanded to cover the whole university we are 
trying to decide how much we can expand the use of groups. At the moment 
we have about 9000 groups in our ldap systems that users may or may not 
want to use in afs acls.

The question that has come up is do we only export the required groups 
or do we just export everything? To answer this we need to better 
understand the PTS groups limitations/features.

So far these are the questions that maybe someone can help me with (I 
can add them into afs wiki as I get answers).

i) What is the maximum group id (i.e. how long before we have to reuse 
the groups ids)?

ii) What is the maximum number of groups (if it is different to i) in pts?

iii) what is the theorectial maximum group membership?

iv) what is the practical maximum group membership?

v) are groups of groups possible?


I am sure there are questions I have not thought of yet but it is a start.

Cheers

Matt