[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference iosg::all-in-1_v30

Title:*OLD* ALL-IN-1 (tm) Support Conference
Notice:Closed - See Note 4331.l to move to IOSG::ALL-IN-1
Moderator:IOSG::PYE
Created:Thu Jan 30 1992
Last Modified:Tue Jan 23 1996
Last Successful Update:Fri Jun 06 1997
Number of topics:4343
Total number of notes:18308

2693.0. "PRIVILEGED USERS AND DRAWERS in the system" by TAV02::SHAPIRA () Tue May 11 1993 08:56

Hi,

I've noticed the following behavior with ALL-IN-1 V3.0:

A priviliged user will see *ALL* the drawers in the system, private or shared,
regardless of tha ACLs on those drawers. He will see all the drawers while
performing the IAD option, thus able to add any drawer in the system to his
file cabinet.

It is right to say that a priviliged user may do anything on the system. Yet,
tha above behavior is different from *violating* the system. In this case,
a user, innocently, may see all the drawers in the system, and add them to his
FC. In many sites, DBAs has full privilegeds, so imagine those users adding
their boss's drawer to their FC.

I have two questions:

1. Is this the intended behavior of V3.0 ?

2. Is it possible to prevent priviliged users from seeing all the drawers in the
   system while using the regular options in the menus ? 

Thanks for any help,
Yariv

T.RTitleUserPersonal
Name
DateLines
2693.1Nothing new here...SCOTTC::MARSHALLSpitfire Drivers Do It ToplessTue May 11 1993 10:4717
Hi,

>> different from *violating* the system. In this case,
>> a user, innocently, may see all the drawers in the system

If a privileged user were to do $ DIR USER1:[000000]*.DIR, they would
"innocently" see everyone's login directory, so I don't think ALL-IN-1 is
giving anything away by showing every drawer to privileged users.

Basically, ALL-IN-1 V3.0 will not let a user do anything they couldn't do
by other means.  What it does do, however, is make more visible the "power"
that a privileged user has.  IE previously "the management" gave their system
managers privileges and because they didn't understand it, didn't worry.  Now
they can better understand it, they worry and will be more careful about who
they give privileges to.  IMVHO that is a good thing.

Scott
2693.2IAD/ADR not equal to drawer accessCHRLIE::HUSTONTue May 11 1993 15:2416
    
    
    As Scott says in .1, they can't do  anything via ALL-IN-1 that they
    cannot do via VMS anyway.
    
    Just because a user can see and add a drawer via IAD, does not mean
    he can access that drawer, or the contents of it.  If the user has
    the OAFC$SYSMAN rights ID the IAD will show all drawers to the user
    (OAFC$SYSMAN means the guy is priv'd as a manager). any drawer can
    be added to anyones file cabinet, there is no access check during 
    the add (sort of like adding any notes conference to your VAX notes
    notebook.). The access checks, and/or existance checks will be done
    when the person tries to access the drawer.
    
    --Bob
    
2693.3Done to death before!IOSG::PYEGraham - ALL-IN-1 Sorcerer's ApprenticeTue May 11 1993 19:383
    This "problem" has been discussed at length earlier in this conference.
    
    Graham
2693.4Which note?COPCLU::ELINElin Christensen @DMO, DTN 857-2406Wed Jun 15 1994 15:1314
>    This "problem" has been discussed at length earlier in this conference.
>
>    Graham

I cannot find it. Could you give me a pointer? 

I have a customer who is worried about what his privileged users might now
realize that they have access to. 
He thinks that there should be something in ALL-IN-1 (datafiles or other 
arrangements) that prevented other users than those explicitly listed in 
ALL-IN-1 drawer administration from getting access to the documents.

Elin
2693.5IOSG::PYEGraham - ALL-IN-1 Sorcerer's ApprenticeWed Jun 15 1994 19:379
    No, I can't offhand, but it has been often discussed and at some
    length. Try some more searches. Or perhaps it was in A1INFO, sincew it
    might have been considered a security risk and hence not wise for
    general view.
    
    Failing that, get someone in Atlanta to search the STARS database of
    all the notes from this conference!
    
    Graham
2693.6for exampleAIMTEC::WICKS_AAtlanta's Most (In)famous WelshmanWed Jun 15 1994 21:001
    note 3227?
2693.7hidden?COPCLU::ELINElin Christensen @DMO, DTN 857-2406Thu Jun 23 1994 11:163
    Note 3227 must be a hidden one. I can't find it.
    
    Elin