At 07:50 PM 19/09/2001 +0000, you wrote:
>Looks like an excellent product (played briefly) but looks weak in terms of
>granting user/group access to specific services.
Oh?
>For instance you can grant access to a Group to the i-bays (although only
>one group!)
If you've ever worked on an NT server where an admin has mixed giving user access to shares and groups you will begin to understand this is actually a by design and very good feature. Users can be members of multiple groups so there is no restriction here just a different way of managing access that is much easier to control/analyse.
>but I'm after real flexibility... for instance under each
>group/user to add an option to allow remote access to each service:
>ssh/ftp/vpn/pop3 etc.
This level of complexity might seem attractive but it's just an additional and IMV unwonted layer. All these services are already controlled by user permissions. If you mean external pop3 access, you don't want it anyway as it is insecure and secure mail access is provided by secure webmail or VPN access. ftp access is controlled by setting group access to the ftp-enabled ibay and making relevent users group members. VPN access gives users the same access to the system remotely as they have locally.
Restricting access to the VPN link could be handy but is a low priority for me - 99% of users wouldn't know how to configure it and is an access issue, not a security issue. Access is logged so if employees are using it who shouldn't be you could just tell them to stop

>That way I can define groups of users whom I wish to grant access to
>specific serivces... much better security.
>Perhaps I'm just missing something, but cannot find anything like this at
>all.