Security Basics mailing list archives

Hi.


From: Matt Stern <sternm () comprehensive com>
Date: Wed, 25 Jun 2003 12:35:14 -0400


Doesn't anyone use the AGLP methodology, meaning:

   1. Create accounts each account (user belongs to one or more):
   2. Global group.  Each global group belongs to one or more:
   3. Local group.
4. Each directory tree/file, whatever, has permissions assigned to the local group.

This way, even hundreds or thousands of logins can easily be maintained, rather than giving rights at the login level. This has always worked for me, both in an NT envronment, and its analogous UGO structure in *nix.

Comments?

--
Matthew H. Stern, CCP/CDP, sternm () comprehensive com
Serving the IT industry since 1986
Comprehensive Computer Services Inc.
www.comprehensive.com
Phone: 631 755-2250, Fax 755-2254
560 Broad Hollow Road, Melville NY 11747



---------------------------------------------------------------------------
Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
The Gartner Group just put Neoteris in the top of its Magic Quadrant,
while InStat has confirmed Neoteris as the leader in marketshare.
Find out why, and see how you can get plug-n-play secure remote access in
about an hour, with no client, server changes, or ongoing maintenance.
Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
----------------------------------------------------------------------------


Current thread: