MSO and multiple communities

Martin Hill mchill at dial.pipex.com
Wed Jul 7 03:11:45 PDT 2004


Guy Rixon wrote:
> On Wed, 7 Jul 2004, Martin Hill wrote:
>>
>>I got the impression that groups allow a coarse-grained approach to
>>assigning privileges and avoid having to track huge numbers of
>>individuals.  Groups can span communities and so separate assigning
>>privilege from trust.  That way we don't need to ask data providers to
>>assign vast numbers of individual privileges.  I'm a bit out of touch
>>though :-(
> 
> 
> Yes, this is the purpose of groups.  However, when controlling access to files
> owned by individuals - think of VOSpace - groups don't avoid the need to
> authorize at the individual level.

I can see that we will want to allow fine-grained privileges too. In the case of 
store space, this is automatic, and individuals look after their own files (and 
who they publish too).  I was more concerned that Wil seems to be saying that we 
would be asking data providers to assign privileges on an individual basis for 
restricted data?


-- 
Martin Hill
www.mchill.net
+44 7901 55 24 66




More information about the grid mailing list