Re: [zfs-discuss] Apache module for ZFS ACL based authorization

2008-09-11 Thread Nicolas Williams
On Thu, Sep 11, 2008 at 10:36:38AM -0700, Paul B. Henson wrote: > On Thu, 11 Sep 2008, Nicolas Williams wrote: > > I bet you think it'd be nice if we had a public equivalent of > > _getgroupsbymember()... > > Indeed, that would be useful in numerous contexts. It would be even nicer > if the approp

Re: [zfs-discuss] Apache module for ZFS ACL based authorization

2008-09-11 Thread Nicolas Williams
On Thu, Sep 11, 2008 at 10:36:38AM -0700, Paul B. Henson wrote: > On Thu, 11 Sep 2008, Nicolas Williams wrote: > > > I bet you think it'd be nice if we had a public equivalent of > > _getgroupsbymember()... > > Indeed, that would be useful in numerous contexts. It would be even nicer > if the app

Re: [zfs-discuss] Apache module for ZFS ACL based authorization

2008-09-11 Thread Paul B. Henson
On Thu, 11 Sep 2008, Nicolas Williams wrote: > I bet you think it'd be nice if we had a public equivalent of > _getgroupsbymember()... Indeed, that would be useful in numerous contexts. It would be even nicer if the appropriate standards body added it alongside of the current getgr* functions to

Re: [zfs-discuss] Apache module for ZFS ACL based authorization

2008-09-11 Thread Nicolas Williams
On Wed, Sep 10, 2008 at 06:35:49PM -0700, Paul B. Henson wrote: > I'd appreciate any feedback, particularly about things that don't work > right :). I bet you think it'd be nice if we had a public equivalent of _getgroupsbymember()... Even better if we just had utility functions to do ACL evaluat

[zfs-discuss] Apache module for ZFS ACL based authorization

2008-09-10 Thread Paul B. Henson
We are currently working on a Solaris/ZFS based central file system to replace the DCE/DFS-based implementation we have had in place for over 10 years. One of the features of our previous implementation was that access to files regardless of method (CIFS, AFP, HTTP, FTP, etc) was completely contro