Re: Lockdown... Take 2




Andrew Sobala wrote:
Can you explain why? If someone wants to prevent users from opening a
terminal, there are 2 ways we can implement this:

* gconf key to hide it plus ACL. Sysadmin has to implement this in two
different places. If someone doesn't read the docs properly and just
goes the gconf way they end up with nonexistant security: they think
it's secure (the menu option doesn't appear) but it can actually still
be run.

True, that's why to make completely secure a sysadmin would need to
use a combination of both Gconf and ACL's

* Just remove access to it in an ACL. Menu items automagically
disappear. Secure, and it "Just Works". If the ACL configuration is
broken, it's obvious to the sysadmin since the menu option is still
there.

How to menu items automagically dissappear.... ?


--
        __.--'\     \.__./     /'--.__
    _.-'       '.__.'    '.__.'       '-._
  .'       Matt Keenan (mattman)          '.
 /       Sun Microsystems Ireland           \
|                                            |
|   E-Mail : Matt Keenan Sun Com             |
|            mattman iol ie                  |
|                                            |
|  Irish Fantasy League Of American Football |
|           http://www.iflaf.com             |
|                                            |
|        Happy Hookers Golf Society          |
|   http://www.iol.ie/~mattman/golf/hhgs.htm |
|                                            |
|   Phone  : +353 1 8199251, Sun Ext : 19251 |
 \         .---.              .---.         /
  '._    .'     '.''.    .''.'     '.    _.'
     '-./            \  /            \.-'
                      ''


--
        __.--'\     \.__./     /'--.__
    _.-'       '.__.'    '.__.'       '-._
  .'       Matt Keenan (mattman)          '.
 /       Sun Microsystems Ireland           \
|                                            |
|   E-Mail : Matt Keenan Sun Com             |
|            mattman iol ie                  |
|                                            |
|  Irish Fantasy League Of American Football |
|           http://www.iflaf.com             |
|                                            |
|        Happy Hookers Golf Society          |
|   http://www.iol.ie/~mattman/golf/hhgs.htm |
|                                            |
|   Phone  : +353 1 8199251, Sun Ext : 19251 |
 \         .---.              .---.         /
  '._    .'     '.''.    .''.'     '.    _.'
     '-./            \  /            \.-'
                      ''




[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]