Re: DENY ACL's

From: Ken Cross (kcross@ntown.com)
Date: 08/20/01


From: "Ken Cross" <kcross@ntown.com>
To: "Ilmar S. Habibulin" <ilmar@watson.org>
Date: Mon, 20 Aug 2001 10:12:49 -0400


>
> > The particular case you show would work, but others won't.
>
> I think that the example given below is the result of badly formed
> security policy.

Not really. There are real cases in large organizations where that
configuration is perfectly legitimate. OTOH, it is often the result of
"quick-fix" solutions. But that's the real world...

>
> > For example, suppose the user is a member of GroupA which is allowed
access
> > and also a member of GroupB which is denied access, e.g. "setfacl -m
> > g:GroupA:rwx,g:GroupB: file". (There's no user-specific ACL.)
> > All "deny" ACL's must be checked first, so the user should be denied.
Under
> > the current scheme, I think the "best match" would allow access.
>
> Yes, user will have access to file, but why shouldn't he have it?

For whatever reason, the administrators decided to explicitly deny access to
GroupB. By definition, that *must* be honored first. I don't make the
rules, but I gotta live by them. ;-)

Ken

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • brad does the neener neener gambit
    ... a faculty member of the College System in Minnesota. ... He made up some lies that he had some reason ... And it was ALWAYS with the strong support of hundreds of other list members. ... ever got any support from other members of lists. ...
    (sci.psychology.psychotherapy)
  • Re: Brian Kernighan, maybe Im not worthy, maybe Im scum
    ... It is obvious that a member function can manipulate variables ... In the cases of A, C, and D, the backslashes shown here do not introduce ... Question 16 is trivial if you discount the possibility that the break ... Nor is there any reason why you couldn't use structs to implement ...
    (comp.programming)
  • Re: British media blackout on Harry, Afghanistan- oh the joys of press freedom
    ... That is the wonder of the British ... may be a senior member of the Royal Family but in this role he was ... is no a priori reason as to why his presence should be given any ... This is not about the Army or "operational reasons". ...
    (uk.politics.misc)
  • Re: jslint doesnt like my syntax for conditional object creation
    ... so long as - member - is a method that really ... being a member or Circle. ... If no such relationships existed then there is no reason for there ... that hierarchy than that namespaces are being simulated. ...
    (comp.lang.javascript)
  • Re: British media blackout on Harry, Afghanistan- oh the joys of press freedom
    ... executive has authorised and bears sovereign responsibility for, ... may be a senior member of the Royal Family but in this role he was ... therefore to keep his presence in theatre secret. ... There was no good reason why the ...
    (uk.politics.misc)