<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to allow secure file access from SFTP processes with different GIDs ? in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/how-to-allow-secure-file-access-from-sftp-processes-with/m-p/4673831#M41844</link>
    <description>&lt;!--!*#--&gt;&amp;gt; [...] In the OpenVMS world [...]&lt;BR /&gt;&lt;BR /&gt;In VMS, a user belongs to exactly one group.&lt;BR /&gt;In a UNIX(-like) OS, a user can belong to&lt;BR /&gt;many groups.  Some things which require an&lt;BR /&gt;ACL in VMS can be done using group&lt;BR /&gt;permissions in GNU/Linux, by adding users to&lt;BR /&gt;the right group.</description>
    <pubDate>Thu, 12 Aug 2010 05:35:58 GMT</pubDate>
    <dc:creator>Steven Schweda</dc:creator>
    <dc:date>2010-08-12T05:35:58Z</dc:date>
    <item>
      <title>How to allow secure file access from SFTP processes with different GIDs ?</title>
      <link>https://community.hpe.com/t5/operating-system-linux/how-to-allow-secure-file-access-from-sftp-processes-with/m-p/4673829#M41842</link>
      <description>Is it possible to allow secure file access from SFTP processes whose primary GID is different ? We do not allow any "other" access. &lt;BR /&gt;&lt;BR /&gt;Say process a has GID of abc and process b has GID of def.  Ideally I want to have all the files and directories to have the group GID as abc. But a non root system process also needs to have access, but the GID is def. In the OpenVMS world we can achieve this with Access Control Lists. &lt;BR /&gt;&lt;BR /&gt;What can be done in the linux world ?</description>
      <pubDate>Thu, 12 Aug 2010 04:17:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/how-to-allow-secure-file-access-from-sftp-processes-with/m-p/4673829#M41842</guid>
      <dc:creator>Thomas Ritter</dc:creator>
      <dc:date>2010-08-12T04:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow secure file access from SFTP processes with different GIDs ?</title>
      <link>https://community.hpe.com/t5/operating-system-linux/how-to-allow-secure-file-access-from-sftp-processes-with/m-p/4673830#M41843</link>
      <description>Answering my own question I find&lt;BR /&gt;&lt;BR /&gt;$ uname -a&lt;BR /&gt;Linux test_box 2.4.21-52.ELsmp #1 SMP Tue Sep 25 15:13:04 EDT 2007 i686 i686 i386 GNU/Linux&lt;BR /&gt;&lt;BR /&gt;$ setfacl --version&lt;BR /&gt;setfacl 2.2.3&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 12 Aug 2010 05:23:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/how-to-allow-secure-file-access-from-sftp-processes-with/m-p/4673830#M41843</guid>
      <dc:creator>Thomas Ritter</dc:creator>
      <dc:date>2010-08-12T05:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow secure file access from SFTP processes with different GIDs ?</title>
      <link>https://community.hpe.com/t5/operating-system-linux/how-to-allow-secure-file-access-from-sftp-processes-with/m-p/4673831#M41844</link>
      <description>&lt;!--!*#--&gt;&amp;gt; [...] In the OpenVMS world [...]&lt;BR /&gt;&lt;BR /&gt;In VMS, a user belongs to exactly one group.&lt;BR /&gt;In a UNIX(-like) OS, a user can belong to&lt;BR /&gt;many groups.  Some things which require an&lt;BR /&gt;ACL in VMS can be done using group&lt;BR /&gt;permissions in GNU/Linux, by adding users to&lt;BR /&gt;the right group.</description>
      <pubDate>Thu, 12 Aug 2010 05:35:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/how-to-allow-secure-file-access-from-sftp-processes-with/m-p/4673831#M41844</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2010-08-12T05:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow secure file access from SFTP processes with different GIDs ?</title>
      <link>https://community.hpe.com/t5/operating-system-linux/how-to-allow-secure-file-access-from-sftp-processes-with/m-p/4673832#M41845</link>
      <description>We are dealing with SFTP operations. AFAIK who cannot change the GID during and SFTP operation. The fundamental problem is we run two major applications, one which if implemented correctly uses virtual uid and gids and other which requires real uid and gids. virtual meaning not in /etc/passwd or /etc/group. The application controls the access. &lt;BR /&gt;&lt;BR /&gt;If the ACL works as I read, then the real uid, gid will be granted access using the acl and others by the application. &lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 12 Aug 2010 05:43:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/how-to-allow-secure-file-access-from-sftp-processes-with/m-p/4673832#M41845</guid>
      <dc:creator>Thomas Ritter</dc:creator>
      <dc:date>2010-08-12T05:43:55Z</dc:date>
    </item>
  </channel>
</rss>

