LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-19-2003, 02:33 PM   #1
bentz
Member
 
Registered: Mar 2003
Distribution: Fedora, Mac OSX
Posts: 362

Rep: Reputation: 30
Groups members of other groups


Is it at all possible to have nested groups, i.e. groups that are members of other groups? I'd like to assign group permissions to a directory, and add groups of users to the group being used for the directory.

/etc/group:
users1:x:500:user1,user2,user3
users2:x:501:user4,user5,user6
resource:x:600:users1,users2

And assigning permissions to the resource:
drwxrwx--- root resource 4096 Jun 19 18:42 directory

and have user1 be able to have rw access to this directory.


Or does it not work this way? Any PAM modules that might do this?
 
Old 06-19-2003, 07:47 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Why not? Did you try it?
 
Old 06-20-2003, 06:12 AM   #3
bentz
Member
 
Registered: Mar 2003
Distribution: Fedora, Mac OSX
Posts: 362

Original Poster
Rep: Reputation: 30
Yeah, it breaks good. It seems like the system doesn't want to go the extra step of granting the user access to the 2nd nested supplementary group. In the above example, the system acts like user1 isn't a member of the resource group.
 
Old 06-20-2003, 07:29 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Damn. Then I see no alternative for you except implement Linux ACL...
 
Old 06-21-2003, 03:14 AM   #5
ebs
LQ Newbie
 
Registered: Jun 2003
Posts: 5

Rep: Reputation: 0
thank for the reply

even i found it helpful
but when i use setfacl command i get the message
"setfacl:test:function not implemented"

can anyone help me for this....would be thankful

cheerio
ebs
 
Old 06-21-2003, 04:39 PM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
...and *what* exactly are you trying to do? We're extemely low on ESP today.
 
Old 06-22-2003, 11:23 PM   #7
ebs
LQ Newbie
 
Registered: Jun 2003
Posts: 5

Rep: Reputation: 0
actually what my problem is that am trying to set the acl entries but am not able to...
when i run the setfacl command with --test option then it shows me the resulting entries but it does not get implemented..
how do i implement it is my prob

i wanna know am i missing upon something,,,,
what has to be taken care of....
if anyone cud help me....for this

willbe thankful...
waiting for the +ve reply

cheerio...
ebs..!!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
groups (system default groups) Xavius Linux - General 2 07-18-2012 02:50 AM
Map Windows NT Groups to UNIX Groups - why? kenji1903 Linux - Networking 4 10-16-2007 11:52 AM
limit to nesting groups within groups? geekgrl Linux - General 3 10-16-2007 11:50 AM
Groups DirtySanchez Linux - Newbie 1 07-28-2005 04:18 PM
winbind: wbinfo -g only lists global groups from PDC and not local groups saradiya Linux - Networking 0 12-01-2003 02:58 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:25 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration