[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]

Re: group membership and terminal lines



Andrew Morgan wrote:
> 
> Currently (pre PAM), all the group permissions are granted based on
> the /etc/group file. For example, Slackware has a "floppy" group that
> users can be members of and get access to a box's floppy drive. It is
> clumsy (or worse) to grant permission to use the floppy drive to a
> user when they are telnetting into a Linux box from the other side of
> the world...
> 

Is there any consensus about a good group structure? Since PAM permits
the session-specific selection of group membership (as opposed to
simply taking the selection found in the /etc/group file), perhaps in
developing PAM, we can develop a group model for access to various
devices on the system...?

A 'floppy' group seems an obvious start. Perhaps we could have a
'mouse' group and also a 'vga' group for access to the monitor (there
is also 'sound' ...). Alternatively, all of these could be in the
'console' group.  Is there a "standard" for this listed anywhere?

Regards

Andrew



[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index] []