summaryrefslogtreecommitdiffstats
path: root/zarb-ml/mageia-discuss/20110307/003921.html
diff options
context:
space:
mode:
Diffstat (limited to 'zarb-ml/mageia-discuss/20110307/003921.html')
-rw-r--r--zarb-ml/mageia-discuss/20110307/003921.html145
1 files changed, 145 insertions, 0 deletions
diff --git a/zarb-ml/mageia-discuss/20110307/003921.html b/zarb-ml/mageia-discuss/20110307/003921.html
new file mode 100644
index 000000000..258b660eb
--- /dev/null
+++ b/zarb-ml/mageia-discuss/20110307/003921.html
@@ -0,0 +1,145 @@
+<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
+<HTML>
+ <HEAD>
+ <TITLE> [Mageia-discuss] Membership handling ( was: Leave )
+ </TITLE>
+ <LINK REL="Index" HREF="index.html" >
+ <LINK REL="made" HREF="mailto:mageia-discuss%40mageia.org?Subject=Re%3A%20%5BMageia-discuss%5D%20Membership%20handling%20%28%20was%3A%20Leave%20%29&In-Reply-To=%3C201103072038.03947.maarten.vanraes%40gmail.com%3E">
+ <META NAME="robots" CONTENT="index,nofollow">
+ <META http-equiv="Content-Type" content="text/html; charset=us-ascii">
+ <LINK REL="Previous" HREF="003914.html">
+ <LINK REL="Next" HREF="003920.html">
+ </HEAD>
+ <BODY BGCOLOR="#ffffff">
+ <H1>[Mageia-discuss] Membership handling ( was: Leave )</H1>
+ <B>Maarten Vanraes</B>
+ <A HREF="mailto:mageia-discuss%40mageia.org?Subject=Re%3A%20%5BMageia-discuss%5D%20Membership%20handling%20%28%20was%3A%20Leave%20%29&In-Reply-To=%3C201103072038.03947.maarten.vanraes%40gmail.com%3E"
+ TITLE="[Mageia-discuss] Membership handling ( was: Leave )">maarten.vanraes at gmail.com
+ </A><BR>
+ <I>Mon Mar 7 20:38:03 CET 2011</I>
+ <P><UL>
+ <LI>Previous message: <A HREF="003914.html">[Mageia-discuss] Membership handling ( was: Leave )
+</A></li>
+ <LI>Next message: <A HREF="003920.html">[Mageia-discuss] test xorg
+</A></li>
+ <LI> <B>Messages sorted by:</B>
+ <a href="date.html#3921">[ date ]</a>
+ <a href="thread.html#3921">[ thread ]</a>
+ <a href="subject.html#3921">[ subject ]</a>
+ <a href="author.html#3921">[ author ]</a>
+ </LI>
+ </UL>
+ <HR>
+<!--beginarticle-->
+<PRE>Op maandag 07 maart 2011 12:34:57 schreef Michael Scherer:
+&gt;<i> On Mon, 7 Mar 2011 12:14:49 +0100, Wolfgang Bornath wrote:
+</I>&gt;<i> &gt; 2011/3/7 Michael Scherer &lt;<A HREF="https://www.mageia.org/mailman/listinfo/mageia-discuss">misc at zarb.org</A>&gt;:
+</I>&gt;<i> &gt;&gt; This bring the question of account management, ie what should
+</I>&gt;<i> &gt;&gt; we do with a account that is explicitely dropped ?
+</I>&gt;<i> &gt;&gt;
+</I>&gt;<i> &gt;&gt; Ie :
+</I>&gt;<i> &gt;&gt; - disable fully
+</I>&gt;<i> &gt;&gt; - leave it as it is now and :
+</I>&gt;<i> &gt;&gt; - disable later
+</I>&gt;<i> &gt;&gt; - leave forever usable
+</I>&gt;<i> &gt;&gt; - disable partially ( ie remove from sensitives groups ( and so
+</I>&gt;<i> &gt;&gt; define
+</I>&gt;<i> &gt;&gt; what group is sensitive ))
+</I>&gt;<i> &gt;&gt;
+</I>&gt;<i> &gt;&gt; So what about last proposal ( remove from sensitive group ) and
+</I>&gt;<i> &gt;&gt; disable
+</I>&gt;<i> &gt;&gt; account
+</I>&gt;<i> &gt;&gt; in 6 months / 1 year ?
+</I>&gt;<i> &gt;
+</I>&gt;<i> &gt; +1
+</I>&gt;<i> &gt;
+</I>&gt;<i> &gt; We've seen it quite often that people re-discover old interests,
+</I>&gt;<i> &gt; hobbies, ex-wives, etc. So, a &quot;sleep time&quot; of 1 year is a good
+</I>&gt;<i> &gt; solution.
+</I>&gt;<i> &gt;
+</I>&gt;<i> &gt; next thing is to define which are &quot;sensitive groups / access
+</I>&gt;<i> &gt; permissions&quot;.
+</I>&gt;<i>
+</I>&gt;<i> Depend on the havoc that could be done by someone stealing a unused
+</I>&gt;<i> account.
+</I>&gt;<i>
+</I>&gt;<i> Someone posting on the forum under a false name will generate lots of
+</I>&gt;<i> drama,
+</I>&gt;<i> but nothing critical. The same goes for bugzilla, or any ml.
+</I>&gt;<i> Now, someone moderating a forum and wrecking havoc would be
+</I>&gt;<i> more problematic. The same goes for svn/git/packages/translation/etc.
+</I>&gt;<i>
+</I>&gt;<i> Maybe it is simple to remove membership from all group, except those
+</I>&gt;<i> seen as
+</I>&gt;<i> unsensitive ? ( ie, everything except default users group ).
+</I>&gt;<i>
+</I>&gt;<i> We also need to see when do we remove such access. IE, if someone after
+</I>&gt;<i> X months
+</I>&gt;<i> decide to find interest into doing stuff that requires Y privileges,
+</I>&gt;<i> what should happen ?
+</I>&gt;<i>
+</I>&gt;<i> - let him do it without asking ( keep Y privileges )
+</I>&gt;<i> - need to ask to have his privileges back
+</I>&gt;<i> - need to redo the whole system from start ?
+</I>&gt;<i>
+</I>&gt;<i> I guess that depending on X and Y, of course, and so we need to have
+</I>&gt;<i> first a list
+</I>&gt;<i> of Y.
+</I>&gt;<i>
+</I>&gt;<i> Let's try with that :
+</I>&gt;<i> - commit to developper svn
+</I>&gt;<i> - commit to packages svn
+</I>&gt;<i> - submit packages
+</I>&gt;<i> - commit to web svn
+</I>&gt;<i> - modifiy ldap
+</I>&gt;<i> - do sysadmin stuff ( log everywhere, touch to config )
+</I>&gt;<i> - planet subscription
+</I>&gt;<i> ( insert bugzilla stuff )
+</I>&gt;<i> ( insert blog privs )
+</I>&gt;<i> ( insert i18n stuff )
+</I>&gt;<i> ( insert forums stuff )
+</I>&gt;<i> ( isert missing stuff )
+</I>&gt;<i>
+</I>&gt;<i> I assume that we can all agree that a leader/deputy/board member
+</I>&gt;<i> resiging will have
+</I>&gt;<i> board/leader/deputy access removed.
+</I>
+[...]
+
+perhaps the user can just opt-out in identity, which could result in:
+ - removal of userPassword attribute, effectively disabling login
+ - and setting a disabled flag in LDAP, which could be taking into account in
+each application.
+ - removal of membership in groups is also an idea. but we'd have to find out
+if there is no &quot;accountability from the past&quot; issue.
+
+this would have the benefit of rejoining at a later time AND the accountability
+from the past of stuff doesn't disappear.
+
+eg: suppose appl X logs what user Y does, and does so with the LDAP reference.
+
+if the ldap entry really is deleted, stuff might go wrong.
+
+just an idea.
+</PRE>
+
+<!--endarticle-->
+ <HR>
+ <P><UL>
+ <!--threads-->
+ <LI>Previous message: <A HREF="003914.html">[Mageia-discuss] Membership handling ( was: Leave )
+</A></li>
+ <LI>Next message: <A HREF="003920.html">[Mageia-discuss] test xorg
+</A></li>
+ <LI> <B>Messages sorted by:</B>
+ <a href="date.html#3921">[ date ]</a>
+ <a href="thread.html#3921">[ thread ]</a>
+ <a href="subject.html#3921">[ subject ]</a>
+ <a href="author.html#3921">[ author ]</a>
+ </LI>
+ </UL>
+
+<hr>
+<a href="https://www.mageia.org/mailman/listinfo/mageia-discuss">More information about the Mageia-discuss
+mailing list</a><br>
+</body></html>