Mandi! Steve Langasek
  In chel di` si favelave...

> Ah - have read the upstream post now, and understand that this is about
> adding users to groups based on whether they're already a member of another
> group.

Yes.


> That doesn't make sense to me, frankly; I think it makes more sense to grant
> the *original* group access to the resources on the system.  So I'm not

I've tried to setup pam_group on some server debian-based i manage.
On some of these i need to lend log-watching permission (eg, group
''adm'') to some unrestricted user, possibly without using complex sudo
setups (they have to read, not execute something).

pam_group works, but i've to list explicitly all users i need, insted
of using the LDAP/Samba group they belong to.
This is and error-prone task, and i can easily forgot some users in
pam_group list...


Also... AFAI've understood, pam_group support add local group to
nisgroup because as the time was written the NIS technology was the
''leader'' in complex networks setup, lead position now gone.
I think that adding network group users to a local group is a perfectly
good option, as was for netgroups.


> inclined to take this patch before it's been applied upstream.

Ok, the best way is:

        http://sourceforge.net/tracker/?group_id=6663&atid=106663

or there's a better one?


Many thanks.

-- 
dott. Marco Gaiarin                                 GNUPG Key ID: 240A3D66
  Associazione ``La Nostra Famiglia''                http://www.sv.lnf.it/
  Polo FVG  -  Via della Bontà, 7 - 33078  -  San Vito al Tagliamento (PN)
  marco.gaiarin(at)sv.lnf.it      tel +39-0434-842711  fax +39-0434-842797

                Dona il 5 PER MILLE a LA NOSTRA FAMIGLIA!
           http://www.lanostrafamiglia.it/chi_siamo/5xmille.php
        (cf 00307430132, categoria ONLUS oppure RICERCA SANITARIA)



--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to