"Matthew V. J. Whalen" writes:
 > >Warning: IP addresses on ACLs don't work on SGIs, they're suspect under
 > >Solaris 2, and there is no similar functionality under DCE/DFS in case
 > >you want to migrate someday.  I wish Transarc would either give this
 > >feature first-class support or come up with an alternative. 
 > >
 > 
 > FWIW, I am currently using IP addresses on ACLs with AFS 3.3a on 
 > Solaris 2.3.
 > 

We've found IP ACLs in afs3.3a to be closer to useless than
we had hoped.

In afs3.2, we came to rely on them for licensed software, especially
the fact that an IP address in the PT server would be handled as
system:authuser.  I guess Transarc thought that was a bug, and
"fixed" IP ACLs.  

What we run into now is that adding an IP address to the PT server,
then adding said IP address to a PT group, doesn't take affect until
the fileserver is restarted for existing directories.  This might even
be the case for newly created directories, I forget.

Once the fileserver has been restarted, IP ACLs work fine.

Add a new IP address, and you have to restart your fileservers.

So I guess it depends on how often you restart your fileservers
and the timing of adding IP addresses to the PT server/groups as
to how well they work for you.

< Paul

Reply via email to