<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://htyp.org/mw/index.php?action=history&amp;feed=atom&amp;title=security_groups</id>
	<title>security groups - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://htyp.org/mw/index.php?action=history&amp;feed=atom&amp;title=security_groups"/>
	<link rel="alternate" type="text/html" href="https://htyp.org/mw/index.php?title=security_groups&amp;action=history"/>
	<updated>2026-08-14T20:23:48Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.3</generator>
	<entry>
		<id>https://htyp.org/mw/index.php?title=security_groups&amp;diff=23495&amp;oldid=prev</id>
		<title>Woozle: slight tidying &amp; update</title>
		<link rel="alternate" type="text/html" href="https://htyp.org/mw/index.php?title=security_groups&amp;diff=23495&amp;oldid=prev"/>
		<updated>2018-01-05T20:02:53Z</updated>

		<summary type="html">&lt;p&gt;slight tidying &amp;amp; update&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 20:02, 5 January 2018&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Computing]]: [[Computing Concepts|Concepts]]: [[User-Group &lt;/del&gt;Security&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;]]: [[security &lt;/del&gt;groups&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|Groups]]&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;&lt;/ins&gt;Security groups&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;&lt;/ins&gt;, also &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;referred to &lt;/ins&gt;as &quot;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;roles&lt;/ins&gt;&quot;, are &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;basic &lt;/ins&gt;concept in &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;multiuser software design&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Groups]]&lt;/del&gt;, also &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;known &lt;/del&gt;as &quot;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Roles&lt;/del&gt;&quot;, are &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;an essential &lt;/del&gt;concept in &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[User-Group Security]]. It is a common solution to the problem of any multi-user system where some users must have access to certain features while other users do not&lt;/del&gt;.&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-added&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The obvious solution is to maintain a list of features to which access must be controlled, and a list of which users are allowed to access (i.e. given &amp;quot;permissions&amp;quot; or [[security rights]] for) each feature. This solution can get complicated, however, when users need to be given additional access, or when they stop working on a particular task and no longer need access to the same things. Where the needed features for one task overlap with those for another task, it is easy to make mistakes and take away too many permissions, or give the wrong ones.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The obvious solution is to maintain a list of features to which access must be controlled, and a list of which users are allowed to access (i.e. given &amp;quot;permissions&amp;quot; or [[security rights]] for) each feature. This solution can get complicated, however, when users need to be given additional access, or when they stop working on a particular task and no longer need access to the same things. Where the needed features for one task overlap with those for another task, it is easy to make mistakes and take away too many permissions, or give the wrong ones.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l17&quot;&gt;Line 17:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 15:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &amp;#039;&amp;#039;&amp;#039;admin&amp;#039;&amp;#039;&amp;#039;, &amp;#039;&amp;#039;&amp;#039;sysadmin&amp;#039;&amp;#039;&amp;#039;, or &amp;#039;&amp;#039;&amp;#039;sysop&amp;#039;&amp;#039;&amp;#039;: highly trusted individual with access to administration functions but not necessarily to everything&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &amp;#039;&amp;#039;&amp;#039;admin&amp;#039;&amp;#039;&amp;#039;, &amp;#039;&amp;#039;&amp;#039;sysadmin&amp;#039;&amp;#039;&amp;#039;, or &amp;#039;&amp;#039;&amp;#039;sysop&amp;#039;&amp;#039;&amp;#039;: highly trusted individual with access to administration functions but not necessarily to everything&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &amp;#039;&amp;#039;&amp;#039;root&amp;#039;&amp;#039;&amp;#039; (in [[Linux]]) or &amp;#039;&amp;#039;&amp;#039;superuser&amp;#039;&amp;#039;&amp;#039;: This user is &amp;quot;god&amp;quot; on the system and can do anything they want. Most security systems try to severely limit the number of root users, although more than one may be necessary in order to provide redundancy (&amp;quot;Jane is out of town on vacation and we need to restart the server!&amp;quot;).&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* &amp;#039;&amp;#039;&amp;#039;root&amp;#039;&amp;#039;&amp;#039; (in [[Linux]]) or &amp;#039;&amp;#039;&amp;#039;superuser&amp;#039;&amp;#039;&amp;#039;: This user is &amp;quot;god&amp;quot; on the system and can do anything they want. Most security systems try to severely limit the number of root users, although more than one may be necessary in order to provide redundancy (&amp;quot;Jane is out of town on vacation and we need to restart the server!&amp;quot;).&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;==Related==&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;* [[Linux/groups]]: the way this is implemented in Linux-like systems&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Woozle</name></author>
	</entry>
	<entry>
		<id>https://htyp.org/mw/index.php?title=security_groups&amp;diff=23494&amp;oldid=prev</id>
		<title>Woozle: Woozle moved page Security groups to security groups without leaving a redirect: not the name of a thing, just a concept</title>
		<link rel="alternate" type="text/html" href="https://htyp.org/mw/index.php?title=security_groups&amp;diff=23494&amp;oldid=prev"/>
		<updated>2018-01-05T20:00:08Z</updated>

		<summary type="html">&lt;p&gt;Woozle moved page &lt;a href=&quot;/mw/index.php?title=Security_groups&amp;amp;action=edit&amp;amp;redlink=1&quot; class=&quot;new&quot; title=&quot;Security groups (page does not exist)&quot;&gt;Security groups&lt;/a&gt; to &lt;a href=&quot;/security_groups&quot; title=&quot;security groups&quot;&gt;security groups&lt;/a&gt; without leaving a redirect: not the name of a thing, just a concept&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 20:00, 5 January 2018&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-notice&quot; lang=&quot;en&quot;&gt;&lt;div class=&quot;mw-diff-empty&quot;&gt;(No difference)&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</summary>
		<author><name>Woozle</name></author>
	</entry>
	<entry>
		<id>https://htyp.org/mw/index.php?title=security_groups&amp;diff=2291&amp;oldid=prev</id>
		<title>Woozle at 15:11, 2 November 2005</title>
		<link rel="alternate" type="text/html" href="https://htyp.org/mw/index.php?title=security_groups&amp;diff=2291&amp;oldid=prev"/>
		<updated>2005-11-02T15:11:11Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[[Computing]]: [[Computing Concepts|Concepts]]: [[User-Group Security]]: [[security groups|Groups]]&lt;br /&gt;
&lt;br /&gt;
[[Groups]], also known as &amp;quot;Roles&amp;quot;, are an essential concept in [[User-Group Security]]. It is a common solution to the problem of any multi-user system where some users must have access to certain features while other users do not.&lt;br /&gt;
&lt;br /&gt;
The obvious solution is to maintain a list of features to which access must be controlled, and a list of which users are allowed to access (i.e. given &amp;quot;permissions&amp;quot; or [[security rights]] for) each feature. This solution can get complicated, however, when users need to be given additional access, or when they stop working on a particular task and no longer need access to the same things. Where the needed features for one task overlap with those for another task, it is easy to make mistakes and take away too many permissions, or give the wrong ones.&lt;br /&gt;
&lt;br /&gt;
This is where the concept of &amp;quot;groups&amp;quot; becomes very useful, because the needed set of [[security rights]] is almost always defined by which system-related tasks or jobs the user is doing. Rather than giving the user each [[security right]] individually:&lt;br /&gt;
* a set of &amp;quot;roles&amp;quot; or [[security groups]] are defined, based on the known jobs or tasks which need to be done&lt;br /&gt;
* then the [[security rights]] needed to do each of those jobs are assigned to the appropriate group(s)&lt;br /&gt;
* [[security users|users]] who are doing those jobs are given membership in the corresponding group(s)&lt;br /&gt;
&lt;br /&gt;
The system then gives each user permissions to access any feature allowed by any of their group memberships; in other words, as long as at least one of their job roles requires a certain feature, they will have access to it &amp;amp;ndash; but if none of their job roles requires a particular feature, they are not given access to it.&lt;br /&gt;
==Common Roles==&lt;br /&gt;
Any user has at least one &amp;quot;role&amp;quot; to play if they are going to interact with a system, even if that role is to be &amp;quot;anonymous&amp;quot; or a &amp;quot;guest&amp;quot; user unknown to the system. Roles common to many systems include:&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;anonymous&amp;#039;&amp;#039;&amp;#039; or &amp;#039;&amp;#039;&amp;#039;guest&amp;#039;&amp;#039;&amp;#039;: this person is unknown to the system, and should not be trusted with any features which could be used to damage the system&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;webmaster&amp;#039;&amp;#039;&amp;#039;: this is a web-server specific role. This user has access to an account on the web server, which usually allows transferring files to/from the server, installation of scripts, and sometimes access to a command-line prompt. This role usually does &amp;#039;&amp;#039;not&amp;#039;&amp;#039; have access to server administration functions.&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;admin&amp;#039;&amp;#039;&amp;#039;, &amp;#039;&amp;#039;&amp;#039;sysadmin&amp;#039;&amp;#039;&amp;#039;, or &amp;#039;&amp;#039;&amp;#039;sysop&amp;#039;&amp;#039;&amp;#039;: highly trusted individual with access to administration functions but not necessarily to everything&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;root&amp;#039;&amp;#039;&amp;#039; (in [[Linux]]) or &amp;#039;&amp;#039;&amp;#039;superuser&amp;#039;&amp;#039;&amp;#039;: This user is &amp;quot;god&amp;quot; on the system and can do anything they want. Most security systems try to severely limit the number of root users, although more than one may be necessary in order to provide redundancy (&amp;quot;Jane is out of town on vacation and we need to restart the server!&amp;quot;).&lt;/div&gt;</summary>
		<author><name>Woozle</name></author>
	</entry>
</feed>