> David Brown posted a workaround for the problem in these apps when you
> first raised the issue:
This isn't a work around.  It's more like trying to fix the wing of an
airplane with duct-tape.  I explored this option in my shop about four
months ago (prior to me even using SME) and it creates several issues that
are not easy to overcome.   This is especially true when roaming profiles
are used.   In one instance, we had a user lose his local profile (including
his email history).

This behavior has been confirmed by several people on the Samba mailing
lists as well as an AutoDesk Tech agent familar with Unix/Samba server
solutions that I spoke with about this.

> Until you can convince me otherwise, I consider these apps to be flawed,
> and for it to be an unacceptable security risk to have all users be
> members of the domain admin group.
More accurately, Samba is flawed as it doesn't correctly interpret the
Windows security model .  Granted windows programmers don't need to write
code that store program information in the system registry, but the horses
have already bolted through the gate on this one.  Autodesk and ESRI are
HUGE companies and we aren't going to change them.  This is a major issue as
millions of people use AutoCAD and Arc/INFO.

> It is an issue, and is one which we will need to deal with, through
> documentation, or through software change if necessary. And until then,
> it's easy for you to use a custom template to solve the problem in the way
> which you see fit.
Sure, I can, but out of the box the average user is going to get smacked
right in the face with this.

This is really no skin off my nose Charlie as I know what the problem is and
how to fix it.  I was simply trying to point it out to you folks as I'm not
the only one on the planet running these apps.

Greg Zartman






--
Please report bugs to [EMAIL PROTECTED]
Please mail [EMAIL PROTECTED] (only) to discuss security issues
Support for registered customers and partners to [EMAIL PROTECTED]
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]
Archives by mail and http://www.mail-archive.com/devinfo%40lists.e-smith.org

Reply via email to