I'm hoping someone can clarify something about the GROUP_MEMBERS_POLICY
check in Nessus3 .audit files.
>From what I read in the documentation, you make a list of users
separated by a pipe sign to specify what members of a given group you
want to check.

What i'm not clear on is if that's a logical AND or logical OR
operation. For example, I might want to make sure the group "foo"
contains members "bob" OR "jane", but not both. Is that possible here?
And similarly, I'd like to have a list of acceptable members for a given
group, but not require they ALL be members. i.e. the Administrators
group may always contain Domain Admins, but may also contain a regional
group depending on its geographic location. I don't want to (and really
can't) implement an audit file for each possible location.

Any suggestions or help would be appreciated. Thanks!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Jeff Mercer - USPS CISO - SVA Team
E-mail: [EMAIL PROTECTED]
Phone : 919-501-9448 
_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to