gnu-arch-users
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Gnu-arch-users] Re: expert needed: arch doesn't support multi-commi


From: Ethan Benson
Subject: Re: [Gnu-arch-users] Re: expert needed: arch doesn't support multi-committer archives!
Date: Wed, 8 Oct 2003 15:53:15 -0800
User-agent: Mutt/1.3.28i

On Tue, Oct 07, 2003 at 01:01:24PM -0400, James Blackwell wrote:
> 
> In lists.arch.users, Ethan wrote:
> >
> > this is not different then a single shared unaccountable account.
> >> * accounting will be logged
> > not in any meaningful way.  unless you only allow connections to the
> > shared account from localhost, forcing a real login first.
> 
> If you think it through, localhost ends up with exactly the same
> problems as remote. Any file a user can write a user can edit, truncate
> or just plain rm. This holds whether we're working on the local
> filesystem or a remote filesystem. There's just no way around that. 
> 
> When you get right down to it, the question you're really asking is "How
> do I let people change files without deleting them or truncating them?
> You don't. 

yes but with process accounting, and authentication logs you have can
have a good idea who was logged in when something occured.  if all you
have is user `sftp' was logged in, where 50 people have access to that
account, you have nothing.

-- 
Ethan Benson
http://www.alaska.net/~erbenson/

Attachment: pgpmfiN5ftQE3.pgp
Description: PGP signature


reply via email to

[Prev in Thread] Current Thread [Next in Thread]