ADSM-L

Re: ADSM/DFS experience

1998-05-21 14:34:05
Subject: Re: ADSM/DFS experience
From: Shyh-Wei Luan <LUAN AT ALMADEN.IBM DOT COM>
Date: Thu, 21 May 1998 11:34:05 -0700
Reinhard,

You wrote:
> Which principal do you use to backup DFS? We have been using root so far,
> but root is considered harmfull by DCE experts because of its property of
> not having to obey ACLs (it's a leftover from NFS). I heard rumours, that
> it might vanish from future DCE releases.

Here I am not particularly arguing for or against the value/problem of giving
the DCE root principal this privilege.  But don't file/backup system admin's
virtually always have (and need to have) the privilege of accessing all files?

Let's focus on the rumor your heard about the DCE root principal's (or its
privilege?) going away.  I checked with Craig Everhart (the DFS team lead
at Transarc), and here is some excerpts from his response.

  "FYI, I know of no truth to that statement.  Currently in Solaris and
  maybe in AIX, there is a patchable kernel variable that allows server
  admins to control whether DCE root is granted permissions.

  Of course, every manufacturer is different, so that's why it's important
  to go to the source for rumors.  How can you help me do that?"

Can you provide Craig the source(s) of this rumor?

Thanks,

Shyh-Wei Luan




--
Shyh-Wei Luan
Shyh-Wei Luan
<Prev in Thread] Current Thread [Next in Thread>