9fans archive / 1997 / 10 / 65 /    prev next

From: Scott Schwartz schwartz+9fans@fin...
Subject: [9fans] group organization
Date: Fri, 24 Oct 1997 00:00:29 EDT

"G. David Butler" <gdb@dbS...> writes:
| Unless you have a large user population with multiple domains of
| administration 

Welcome to *.edu.  

| the group concept is simpler and sufficient.

It's simpler to code, but not simpler to use.

My experience is that in small organizations, everything is world
readable, owner writable, and there's one big group that everyone
(except for e.g. uucp) is in so you can have almost-world-writable
directories.  ACLs are much nicer.

| (A group is just a ACL "macro".) 

I disagree.  Under that regime, in order to give a person new access to
a file, you have to create a new group, dragging the authentication
server into the picture every time you want to adjust some file.
Worse, if you really use that scheme, you can end up with an 
unsightly number of such groups.