On Wed, Apr 04, 2007 at 09:13:58AM -0700, Adam Chlipala wrote:
> Adam Megacz wrote:
> > Adam Chlipala <[EMAIL PROTECTED]> writes:
> >   
> >>> so I'm suspecting that groups aren't "recursive", but then 
> >>> what is the point of allowing groups to be members of other groups
> >>> in the first place?)
> >>>       
> >
> > They are supposed to be recursive in OpenAFS >= 1.4.0.
> >
> > Is there still an outstanding problem with
> > domtool.service/domtool.deleuze, or did that get solved?
> >   
> 
> I don't think I've encountered any problems with those since docelic's 
> last message about principals & permissions.
> 
> However, I think the issue with database permissions is still open.

I've verified that we do have --enable-supergroups compile-time option
which makes group behave resursively.

And I've tested one case where it works. As long as you add 
mysql.service rl and postgres.service rl manually, we'll have time
to fully troubleshoot 'databases' group later..


(Also, I figured just now that I didn't mention it explicitely, all other
fs setacl commands that are run as part of db creation, and that previously
were giving permissions to mysql and postgres, now need to do it to
mysql.service and postgres.service . So please update this bit.)


-doc

_______________________________________________
HCoop-SysAdmin mailing list
[email protected]
http://hcoop.net/cgi-bin/mailman/listinfo/hcoop-sysadmin

Reply via email to