- Summary of discussions to date
- Statements of position... this is what we had after the DB in London:
"The UK(I) does not accept glexec in its present state and will not recommend its deployment (note to UK only, some sites may ignore that advice). Before we will reconsider its deployment we require to see:
a) a satisfactory code inspection wrt security.
b) an AUP with VOs agreed in principle by sites (in general through GDB) and all 4 LHC VOs.
c) a satisfactory analysis of the effect on the supported batch systems and accounting of identity changes.
d) glexec should be simple and safe to configure. Simple so that all sysadmins can understand what they are doing and safe so that misconfigurations do not inadvertently lead to security exposures.
e) The three flavours of glexec should exist as separate binaries and not as one with a configuration switch. Each of these should satisfy all package dependencies. e.g., dependencies should express some requirement for an abstract "glexec" property, which is satisfied by "glexec-null" or "glexec-suid" etc.
"