IWETHEY v. 0.3.0 | TODO
1,095 registered users | 1 active user | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New Besides which, I am under the impression
that the userid/groupid model in unix is just a wrapper around ACLs anyway.
--\n-------------------------------------------------------------------\n* Jack Troughton                            jake at consultron.ca *\n* [link|http://consultron.ca|http://consultron.ca]                   [link|irc://irc.ecomstation.ca|irc://irc.ecomstation.ca] *\n* Kingston Ontario Canada               [link|news://news.consultron.ca|news://news.consultron.ca] *\n-------------------------------------------------------------------
New My impression contradicts that
I have come to believe that idealism without discipline is a quick road to disaster, while discipline without idealism is pointless. -- Aaron Ward (my brother)
New Nah.
ACLs is a bolt-on in Linux.

Proprietary UNIX has more integrated support.


Peter
[link|http://www.no2id.net/|Don't Let The Terrorists Win]
[link|http://www.kuro5hin.org|There is no K5 Cabal]
[link|http://guildenstern.dyndns.org|Home]
Use P2P for legitimate purposes!
New Bolt-on? How so?
It either works on the file system or it doesn't.

Only certain Filesystems actually support it. To the Kernel it is as much a bolt-on as is any of the loadable modules are. It is in the Core Kernel tree. How is that a Bolt-on? You could compile it into the kernel just like filesystem support, *IF* you wanted. Then you have to enable it on the filesystem in question.

Now, Pile-on I can buy. ACLs are on-top of existing UGO stuff.

Now, if you are talking about easy-to-use Point-n-drool... Sure, commercial *NIX have it better off. But would you REALLY call SAM in HPUX a *GOOD* interface for it? Or rather ANY of the Administration tools that commercial *NIX systems have? Hell I'd rather use Linuxconf with a custom module than any of those. Or even Webmin.

One thing Microsoft's stuff hasn't gotten right yet... is letting you into a Directory, then give you full read and execute in a sub-directory, without bleeding through the rights mask and screwing up the parent directory. You have to address it file by file.

Now, speaking of your beloved VMS, yes there is great model of security, Bolted on... but in replacement of other mechanisms... and rules with not just an Iron-Fist... but also a Powered-War-Hammer, as a fallback, has a auto-targetting-never-miss Sniper Rifle with quite few miles of range (real limits unknown). IOW, if you should not even know of the existance of a certain object/file/device... you'll have zero clue about it.
--
[link|mailto:greg@gregfolkert.net|greg],
[link|http://www.iwethey.org/ed_curry|REMEMBER ED CURRY!] @ iwethey
Freedom is not FREE.
Yeah, but 10s of Trillions of US Dollars?
SELECT * FROM scog WHERE ethics > 0;

0 rows returned.
     ACLs versus UNIX User:Group security? - (inthane-chan) - (14)
         if you mean access lists (ACL) you need both - (boxley)
         Remember, complex does not mean secure - (ben_tilly) - (9)
             Besides which, I am under the impression - (jake123) - (3)
                 My impression contradicts that -NT - (ben_tilly)
                 Nah. - (pwhysall) - (1)
                     Bolt-on? How so? - (folkert)
             On "real security weenies"... - (inthane-chan) - (4)
                 But some are better than others - (ben_tilly) - (3)
                     Awooga! Pedant alert! - (pwhysall)
                     except for the giant gapers in it, ask skip offline -NT - (boxley) - (1)
                         Will do but... - (ben_tilly)
         Linux has both. - (broomberg)
         UNIX has ACLs. - (pwhysall) - (1)
             see my "Bolt on? How so?" post. -NT - (folkert)

Then again, I think our walls are made from the salvaged hulls of exotic alien spacecraft so YMMV.
45 ms