| >
| > I actually had in mind an unlimited parent/child relationships in
| > the groups. So that the super-parent would be the "Admin" group,
| > that all other groups are derived from, like "superusers" inherit
| > the rights from the admin group, but with rights X,Y & Z revoked.
| > And the "regular users group" is a child of the "superusers" group,
| > etc.
|
| You do realize this is a "fail open" model? I.e., if somehing goes
| wrong the user defaults to being Admin, instead of being nobody. Most
| security systems are designed as "fail close" systems.
|
| Jochem
Mmm... I just realized that. I guess the alternative would be that all
groups are inheriting from the "guest/unpriviliged group" (deny
everything).
But it could also be designed so that there is a setting "do not inherit
from parent" for a group, and also so that a user defaults to being in no
group at all (no rights to inherit).
/H.
###########################################
This message has been scanned by F-Secure Anti-Virus for Microsoft
Exchange.
For more information, connect to http://www.F-Secure.com/
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings]

