home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!noc.near.net!news.Brown.EDU!stout!robinson
- From: robinson@stout.geo.brown.edu (Darrin Robinson)
- Newsgroups: comp.os.vms
- Subject: Re: BACKUP Question
- Date: 9 Nov 1992 13:31:26 GMT
- Organization: Brown University, Providence RI 02912
- Lines: 58
- Distribution: world
- Message-ID: <1dlp7eINNc1r@cat.cis.Brown.EDU>
- References: <9211062238.AA11641@hermann.barra.COM>
- NNTP-Posting-Host: stout.geo.brown.edu
-
- In article <9211062238.AA11641@hermann.barra.COM> louis@BARRA.COM (Louis Dunne) writes:
- >On Nov 3, 10:04pm, Mark Wilton 23313 wrote:
- >> Subject: Re: BACKUP Question
- >>TKENNETT@BENTLEY.BITNET writes:
- >>
- >>>Hello,
- >>
- >>>My question is this: Is it possible to BACKUP files from disk to tape in a way
- >>>which prevents another user from restoring the files.
- >>
- >>
- >>> _or_
- >>>Ted Kennette
- >>>tkennett@bentley.bitnet
- >>
- >>
- >>Um taking the tape from the drive and putting it somewhere secure
- >>always seems to work for me 8^]
- >>
- >
- > I know the last reply was light hearted but I think the following
- > is worth mentioning.
- >
- [stuff deleted...]
-
- > There are many steps you can do to prevent everyday users from using
- > your tape drive(s) and/or tapes. My suggestion would be a device
- > level ACL on the tape device(s), and change the device protection to
-
- Better yet, operationally, have the operators ALLOCATE the device before
- putting ANY tape on-line! This will ensure that only PRIVILEGED people
- with a DEALLOCATE program could EVER get the device without the Operator
- DEALLOCATING the tape drive explicitly, or by loggin gout.
-
- > prevent world (and maybe group) access. Then grant that identifier
- > to the "authorized" users of the device. If there are a small number
- > of users who you want to restrict, then do the resverse. Put an ACL
- > on the device which prevents access by a set of users; then grant
- > that identifier to those users. I think this is the reasonably
- > easy "painfree" solulion.
- >
-
- The ACL is a pretty secure way of securing the device, but leaves the
- device totally unavailable to a user or group of users. If no-one but
- Privileged users use the tape-drive, or SHOULD use the tape drive, then
- this is probably the BEST solution.
-
- >
- >Louis
- >
-
- Darrin
- . Darrin E. Robinson (DER31) Hamnet N1LLV 146.700-, 146.880= MHz
- /| Systems Programmer II Internet darrin@mit.edu
- \| Dist. Computing & Network Services robinson@porter.geo.brown.edu
- |\ MIT Information Systems ICBMnet 41 29 24 N 71 18 48 W (NPT)
- |/ 1 Amherst St. - Rm E40-338 NASAmail derobinson@nasamail.nasa.gov
- . Cambridge, MA 02319 AT&Tnet (617) 253-0131
-