From: Alistair Y. <ali...@sm...> - 2006-06-29 13:32:18
|
ok, that's confusing now! The Group tool states: sysadmins : System administrators for this web site > The group with all the power is the /site owners group > which by default contains sysadmin do you mean the sysadmin user or the sysadmins group? The Group tool seems to state that adding someone to the sysadmins groups makes them a sysadmin with all rights over the whole site. So whether they end up in the sysadmins group via the Group tool or the shibb auth shouldn't make any difference. But it does for some reason. Alistair On 29 Jun 2006, at 14:27, Matthew Buckett wrote: > Alistair Young wrote: >> Interesting question and the answer I suspect depends on the answer >> to this one: >> >> I logged in to Bod1 using Bod2 as an IdP. I logged in as sysadmin on >> Bod2's IdP and got into Bod1 using the shibb authenticator but wasn't >> made a sysadmin. I was put into the sysadmins group as >> sys...@ww.... > > The sysadmin group doesn't get any extra rights in a standard Bod > install I think. The group with all the power is the /site owners > group > which by default contains sysadmin and has sysadmin permission. > > If you grant the sysadmin group sysadmin permission to the /site > resource this should work. > >>> Is it possible to set it up to allow both shibb and another >>> authentication mechanism to work at the same time? > > The reason I asked was we currently have 3 authentication methods > (anonymous, internal and WebAuth) here at Oxford. > > -- > -- Matthew Buckett, VLE Developer > -- Learning Technologies Group, Oxford University Computing Services > -- Tel: +44 (0)1865 283660 http://www.oucs.ox.ac.uk/ltg/ > > Using Tomcat but need to do more? Need to support web services, > security? > Get stuff done quickly with pre-integrated technology to make your > job easier > Download IBM WebSphere Application Server v.1.0.1 based on Apache > Geronimo > http://sel.as-us.falkag.net/sel? > cmd=lnk&kid=120709&bid=263057&dat=121642 > _______________________________________________ > Bodington-developers mailing list > Bod...@li... > https://lists.sourceforge.net/lists/listinfo/bodington-developers |