[OpenAFS] Help: Client side permission denied when access the volume

Jeffrey Altman jaltman@secure-endpoints.com
Fri, 10 Jun 2011 08:46:19 -0700


This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enigA79EA63641E0F066C553D53E
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

On 6/10/2011 8:41 AM, Lee Eric wrote:
> Yes mate, I know the OpenAFS permission is not the same with the UNIX
> ACL. But according to my ACL set up the user "huli" could access the
> /afs/herdingcat.internal/home/huli this dir.
>=20
> Eric

That would be fine if it were possible for operating systems to provide
access to the 'huli' directory without also being able to list the
contents of every directory above it in the path.  You have granted no
permissions to /afs to anyone other than the system.administrators.  As
a result it is impossible to find out that 'herdingcat.internal' exists
let alone 'home' and 'huli'.

Jeffrey Altman


--------------enigA79EA63641E0F066C553D53E
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)

iQEcBAEBAgAGBQJN8jxOAAoJENxm1CNJffh4/EwIAJ+pWLmcJxNtQVZdYNV0wn7x
ClB5lqOrRZsw9c7OQrWamUGyLM6aS8fUWQ88kniVaK+b93Tmpe5zMf49lqpIq8gO
ImBolq4WN9n7ODPvjyXF6YTXIgtJ+YhyFvYJnDtcl+bfGdqrd6TfF/5w0OSzkRYb
xAtI3AFeGXj/V+fUM6mutB/e8b699VJ3EgB6U8cq6qYgFxZMDAbPOkTKvSdTaMNg
Bbz03IR0+hYf2lawTWtqt2iJJWK6oYn6HSc1Abb4kr4FBf1VEd1VUTiqYaym+pCP
6+svwAIiyRBe0mJMS2OSWB8h6XtMzlcPz1SvViQ/ptRT7CyZlrJ634AyevSeS+4=
=NSKz
-----END PGP SIGNATURE-----

--------------enigA79EA63641E0F066C553D53E--