[comp.protocols.tcp-ip.ibmpc] Secondary GID access over PC-NFS

ttl@sti.fi (Timo Lehtinen) (10/09/90)

Does anyone know if it's possible to allow a PC-NFS user NFS access
from the PC using more than one group ID?  I.e. the equivalent of the 
BSD UNIX /etc/group mechanism. The current implementation of pcnfsd 
seems to just return the primary GID associated with the user (defined 
in /etc/passwd) and that is used. We have a need to authorize a PC-NFS 
user to more than one group!

Any hack around this would be much appreciated!

Timo

-- 
       ____/ ___   ___/    /		Kivihaantie 8 C 25
      /           /       /		SF-00310 HELSINKI, Finland
   ____  /       /       /	Phone:	+358 0 573 161, +358 49 424 012
  Stream Technologies Inc.	Fax:	+358 0 571 384

root@leuze.UUCP (Operator) (10/10/90)

ttl@sti.fi (Timo Lehtinen) writes:

>Does anyone know if it's possible to allow a PC-NFS user NFS access
>from the PC using more than one group ID?  I.e. the equivalent of the 
>BSD UNIX /etc/group mechanism. The current implementation of pcnfsd 
>seems to just return the primary GID associated with the user (defined 
>in /etc/passwd) and that is used. We have a need to authorize a PC-NFS 
>user to more than one group!

In PC-NFS 3.0.1 this works well.
But the setuid - setgid scheme does NOT work because of bugs in PC-NFS.

Regards, Fritz

 (-:   Fritz B. Raab                 |   email: fbraab@leuze-owen.de        :-)
 (-:   Leuze electronic, Abt. TDV    |   old:   ..uunet!unido!leuze!fbraab  :-)
 (-:   In der Braike 1               |          fbraab@leuze.uucp           :-)
 (-:   D7311 Owen / Teck W.Germany   |   voice: +49 7021 573185 fax: 573200 :-)

ttl@sti.fi (Timo Lehtinen) (10/12/90)

In article <1536@leuze.UUCP> root@leuze.UUCP (Operator) writes:
>ttl@sti.fi (Timo Lehtinen) writes:
>
>>Does anyone know if it's possible to allow a PC-NFS user NFS access
>>from the PC using more than one group ID?  I.e. the equivalent of the 
>>BSD UNIX /etc/group mechanism. The current implementation of pcnfsd 
>>seems to just return the primary GID associated with the user (defined 
>>in /etc/passwd) and that is used. We have a need to authorize a PC-NFS 
>>user to more than one group!
>
>In PC-NFS 3.0.1 this works well.
>But the setuid - setgid scheme does NOT work because of bugs in PC-NFS.
>
>Regards, Fritz

Huh? In the first sentence you say that it "works well", and in the second
that it "does NOT work because of bugs in PC-NFS"... 

I was kindly informed via mail that by using YP this would actually work. 
I have only tested it with pcnfsd, so I can't comment on that. However,
we would not want to start using YP just in order to get multiple groups 
working with PC-NFS. Pcnfsd seems such a nice little utility for the task
and apart from this has worked flawlessly.  It would really be nice to
get multiple groups to work with pcnfsd ? Since it works with YP what's 
the basic difference between YP and pcnfsd in this respect from the PC's
point of view why it can't work with pcnfsd too ?  What I would like to
know is can it be fixed or not ...

Thanks,

Timo






-- 
       ____/ ___   ___/    /		Kivihaantie 8 C 25
      /           /       /		SF-00310 HELSINKI, Finland
   ____  /       /       /	Phone:	+358 0 573 161, +358 49 424 012
  Stream Technologies Inc.	Fax:	+358 0 571 384