[Techtalk] dropping group memberships/privileges

Riccarda Cassini riccarda.cassini at gmx.de
Mon Oct 18 22:13:18 EST 2004

On Mon, Oct 18, 2004 at 02:01:08PM -0500, Listpig wrote:
> Given that you might need those privileges again and you're probably going
> to have to go to whoever has root anyhow to get a change made, might it not
> be preferable to ask instead for a specific test account to be created that
> you can customize in terms of what it's allowed to do?

As a last resort, I guess I'll probably have to do this. Unfortunately,
there's always a rather large administrative (political) overhead to
get a new account at all.  That's what I wanted to avoid, if possible.
Along similar lines, I certainly do not want to have my current
hard-won group memberships altered permanently - it took me quite some
time to get into those groups in the first place ;-)  (and I do need
them for other purposes...)

What I was thinking of was, to just drop privileges temporarily for
some subshell or a single command - essentially the same way that
newgrp(1) operates, only affecting supplementary groups... But if there
is no way, I'll try to get a test account set up  (or try to just
code more carefully... :-)


