Re: Need creative solution to only change ACL by owner problem

"Mont Rothstein" <[email protected]> Wed, 2 Aug 2006 11:41:01 -0700
Newsgroups gmane.linux.file-systems.acl.devel
Message-ID <[email protected]>
--===============0993004047==
Content-Type: multipart/alternative; 
	boundary="----=_Part_42992_20810547.1154544061589"

------=_Part_42992_20810547.1154544061589
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

Thanks for the suggestions.

I'm currently playing with creating an account that we own all files and
folders and then having users impersonate that account.

Far from ideal, but I have to use samba and need to be able to grant
individual users permission to access a file.

Thanks,
-Mont


On 8/1/06, Matt McCutchen <[email protected]> wrote:
>
> On 7/31/06, Mont Rothstein <[email protected]> wrote:
> > I just learned that only the owner of a file/directory or root can
> change
> > the ACLs.  We need anyone with the correct permissions to be change the
> ACLs
> > so that other users can be granted access.
>
> A few things you might try:
> - You could put everyone who is to have access in a group and give the
> group access to the files and directories.  Then you could set some or
> all of the members as group administrators with gpasswd, allowing them
> to add new members.
> - Use AFS because its ACLs have an "a" permission that governs
> changing permissions.
> - There's always a way to do these things with setuid programs, but
> they're ugly and difficult to make secure.
>
> Matt
>

------=_Part_42992_20810547.1154544061589
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

Thanks for the suggestions.<br><br>I'm currently playing with creating an account that we own all files and folders and then having users impersonate that account.<br><br>Far from ideal, but I have to use samba and need to be able to grant individual users permission to access a file.
<br><br>Thanks,<br>-Mont<br><br><br><div><span class="gmail_quote">On 8/1/06, <b class="gmail_sendername">Matt McCutchen</b> &lt;<a href="mailto:[email protected]">[email protected]</a>&gt; wrote:</span><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
On 7/31/06, Mont Rothstein &lt;<a href="mailto:[email protected]">[email protected]</a>&gt; wrote:<br>&gt; I just learned that only the owner of a file/directory or root can change<br>&gt; the ACLs.&nbsp;&nbsp;We need anyone with the correct permissions to be change the ACLs
<br>&gt; so that other users can be granted access.<br><br>A few things you might try:<br>- You could put everyone who is to have access in a group and give the<br>group access to the files and directories.&nbsp;&nbsp;Then you could set some or
<br>all of the members as group administrators with gpasswd, allowing them<br>to add new members.<br>- Use AFS because its ACLs have an &quot;a&quot; permission that governs<br>changing permissions.<br>- There's always a way to do these things with setuid programs, but
<br>they're ugly and difficult to make secure.<br><br>Matt<br></blockquote></div><br>

------=_Part_42992_20810547.1154544061589--

--===============0993004047==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
acl-devel mailing list
[email protected]
http://acl.bestbits.at/mailman/listinfo/acl-devel

--===============0993004047==--