ACLs are good and very usefull.
HOWEVER, there are cases of users giving away their files to users
that are not authorized to recieve that data.
The advantage of groups is that the facility managment defines the
list of users authorized to view the data. It up to the user to
grant/deny that group access authorization.
Alternatively, it is possible to view the system as you describe - the
user can add others to the ACL to grant access. There should still be
some method that facility management can deny access.... On many systems
(Trusted Solaris, UNICOS, Trix,...) this is done with compartmentalization.
Now, it is subsets of the members of the compartment that the user can
grant access to.
Still more flexible than generic groups, but more restricted than no
limits on members of the ACL.
-- ------------------------------------------------------------------------- Jesse I Pollard, II Email: jesse@cats-chateau.netAny opinions expressed are solely my own. - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/