Re: Need creative solution to only change ACL by owner problem
"Mont Rothstein" <[email protected]> Wed, 2 Aug 2006 11:41:01 -0700
| Newsgroups | gmane.linux.file-systems.acl.devel |
|---|---|
| Message-ID | <[email protected]> |
--===============0993004047== Content-Type: multipart/alternative; boundary="----=_Part_42992_20810547.1154544061589" ------=_Part_42992_20810547.1154544061589 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline Thanks for the suggestions. I'm currently playing with creating an account that we own all files and folders and then having users impersonate that account. Far from ideal, but I have to use samba and need to be able to grant individual users permission to access a file. Thanks, -Mont On 8/1/06, Matt McCutchen <[email protected]> wrote: > > On 7/31/06, Mont Rothstein <[email protected]> wrote: > > I just learned that only the owner of a file/directory or root can > change > > the ACLs. We need anyone with the correct permissions to be change the > ACLs > > so that other users can be granted access. > > A few things you might try: > - You could put everyone who is to have access in a group and give the > group access to the files and directories. Then you could set some or > all of the members as group administrators with gpasswd, allowing them > to add new members. > - Use AFS because its ACLs have an "a" permission that governs > changing permissions. > - There's always a way to do these things with setuid programs, but > they're ugly and difficult to make secure. > > Matt > ------=_Part_42992_20810547.1154544061589 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline Thanks for the suggestions.<br><br>I'm currently playing with creating an account that we own all files and folders and then having users impersonate that account.<br><br>Far from ideal, but I have to use samba and need to be able to grant individual users permission to access a file. <br><br>Thanks,<br>-Mont<br><br><br><div><span class="gmail_quote">On 8/1/06, <b class="gmail_sendername">Matt McCutchen</b> <<a href="mailto:[email protected]">[email protected]</a>> wrote:</span><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;"> On 7/31/06, Mont Rothstein <<a href="mailto:[email protected]">[email protected]</a>> wrote:<br>> I just learned that only the owner of a file/directory or root can change<br>> the ACLs. We need anyone with the correct permissions to be change the ACLs <br>> so that other users can be granted access.<br><br>A few things you might try:<br>- You could put everyone who is to have access in a group and give the<br>group access to the files and directories. Then you could set some or <br>all of the members as group administrators with gpasswd, allowing them<br>to add new members.<br>- Use AFS because its ACLs have an "a" permission that governs<br>changing permissions.<br>- There's always a way to do these things with setuid programs, but <br>they're ugly and difficult to make secure.<br><br>Matt<br></blockquote></div><br> ------=_Part_42992_20810547.1154544061589-- --===============0993004047== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ acl-devel mailing list [email protected] http://acl.bestbits.at/mailman/listinfo/acl-devel --===============0993004047==--