home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: vmsnet.sysmgt
- Path: sparky!uunet!pipex!ibmpcug!miclon!nreadwin
- From: nreadwin@micrognosis.co.uk (Neil Readwin)
- Subject: Re: Here is a ACL question for you!
- Message-ID: <C1Go77.LIx@micrognosis.co.uk>
- Sender: news@micrognosis.co.uk
- Organization: Micrognosis, a division of CSK(UK) Ltd
- References: <4630@mitech.com>
- Date: Tue, 26 Jan 1993 12:33:07 GMT
- Lines: 13
-
- In article <4630@mitech.com>, gjc@mitech.com (George J. Carrette) writes:
- |> Is it possible to prevent a user from being able to
- |> change the protection on a directory that he owns?
-
- No. If you look at the Guide to VMS System Security you will find (Figure
- 4-4) a flowchart. Even if an ACL explicitly denies access then it will
- branch off to BB (UIC based checks). If the requester UIC is the owner UIC
- then it checks the protection code for the object. If you read between the
- lines of section 4.2.3 then it is clear that UIC based protection always
- grants CONTROL access to the owner.
- --
- Phone: +44 71 815 5283 E-mail: nreadwin@micrognosis.co.uk
- Anything is a cause for sorrow that my mind or body has made
-