On Wed, Sep 09, 2009 at 07:34:24AM +0200, Borzenkov, Andrey wrote:
If you do not trust domain administrators, remove them from local administrators group on filer and/or implement finer grained role restrictions.
But this does not soleve the problem methinks. I want them to be able to set up shares in the volumes they need to. I just do not want them to be able to set up shares to oracle databases on the same filer.
One solution would be virtual filers (forget the name of that feature for the monent). Then I could have the oracle volumes on seperate virtual filers to the shares. But thats a lot of bother.
Regards, pdg
--
See mail headers for contact information.