[OpenAFS] Re: Ideas for finer grain set acl controls

Andrew Deason adeason@sinenomine.net
Thu, 12 Nov 2009 14:12:27 -0600

On Thu, 12 Nov 2009 14:51:11 -0500
Michael Meffie <mmeffie@sinenomine.net> wrote:

> > It seems to me that restricting system:authuser would be less common
> > than anyuser/anonymous, but it still could be useful; and we have
> > other methods that cover the use case.
> I'm failing to see a use case here. Anyone on this list have a
> concrete example?

In other words: *** PLEASE SPEAK UP *** if you want to be able to
prevent normal users from doing something like "fs setacl ${HOME}
system:authuser rlidwka" even when they have the 'a' bit on ${HOME}.

Even if it's just "+1, yes, I want that", please say something.

Andrew Deason