Hi char22,
Are you trying to go by the "lockdown" as described in the sec admin guide?
Lets take the pre-assignment out of the picture for a moment, and please correct me if I misunderstood:
You have several groups.
Some of these groups are allowed to read/write/delete metadata, while others are not allowed to delete.
Is the problem that the same users are in different groups, allowed to delete/read/write with one group, but
not with the other?
(I am trying to find out if the issue might be due to conflicting permissions).
Or,
is the problem that you simply have different groups, with different permissions, where some groups can and some
cannot delete?
Next:
Please provide an example where you describe exactly how the security set up is supposed to be.
Such as:
data A
Group A deny for delete/wm/rm
Group B grant for ...
this is the behavior: ...
Does that make sense, do you know where I am getting at with this?
Thanks
Anja
... View more