Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 226869
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 11, 20262026-05-11T19:33:04+00:00 2026-05-11T19:33:04+00:00

I have been asked to look at how to restrict read access on certain

  • 0

I have been asked to look at how to restrict read access on certain VOBs in ClearCase, for compliance reasons (so this needs to be auditable, etc, etc…). I have found a solution so far, that I will post here, but I still have questions, so any help would be appreciated. Especially as the devil is in the details, I think.

For ease of argument, let say we have 3 VOBs, and 3 groups:

  • gA and gB are two special group, all other CC users are in gC, which is the default CC group
  • VOB vA, is read/write access to group gA, and restricted to everybody else
  • VOB vB, is read/write access to group gB, read access to group gA, and restricted to everybody else
  • VOB vC, is read/write access to everybody

Unaswered questions:

  • What is the impact in having different Domain groups for CC users ? When people log, their clearcase group is picked-up by the user variable CLEARCASE_PRIMARY_GROUP. If they are from gA and are working normally in vA, this variable will be set up to gA, but if they need to change something in vC, I bet that the group ownership of their files/versions in vC will stay gA if they don’t do anything about it. Objects in vC will end up having group-belonging to gA, gB, gC. Can that be a problem ?

  • I am not even sure it is possible to set up ACLs properly on vB without in fact creating a new group, gA’ containing people from both gA and gB, am I right ?

  • It seems to me the difficulty here is not technical, but rather that in the process for giving access to certain people to the proper groups, and that the CM team should stay away from this (and leave that to be decided by the Security Department and the development teams involved). Anyone has any experience in this matter ?

  • It seems that it is possible to use ClearCase Regions to achieve the same effect. How would that work ?

Best regards,

Thomas

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-11T19:33:04+00:00Added an answer on May 11, 2026 at 7:33 pm

    So far, I have found this answer from the IBM developerworks forums:

    (edited)

    1. Create two additional Domain groups for the teams

    2. Add the appropriate new Domain group to each ClearCase user’s groups profile (in addition to the gC group membership they already have).
      You’ll want the vobadmin account to be a member of both these new groups.

    3. Change the group ownership of the VOBs accordingly:
      cleartool protectvob -chgrp group_name <\\..vob.vbs>
      gA for vA
      gB for vB
      gC for all other VOBs (it should already be the case)

    4. Remove the “other groups” permissions from the root element of
      the vA and vB VOBs:
      cleartool protect -chmod 770 <vob-tag-name>
      You can also do this by using CC Explorer: right-click on the VOB in
      any view and select “Properties of Element”. There’s no need to
      re-protect the entire VOB (Note: this is important for me, because reprotecting the whole VOB takes a long time, and I have more than 200 VOBs here).

    Now, only members of the gA group will have access to the vA VOB.
    Only members of the gB group will have access to the vB VOB.
    Everybody is a member of the gC group so everybody will have access to all
    other VOBs.

    Note that you will want to set the CLEARCASE_PRIMARY_GROUP environment
    variable for a particular user if you want newly created objects by that
    user to be owned by a group different from that user account’s Primary Group
    as it is set in the Domain Controller.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Ask A Question

Stats

  • Questions 124k
  • Answers 124k
  • Best Answers 0
  • User 1
  • Popular
  • Answers
  • Editorial Team

    How to approach applying for a job at a company ...

    • 7 Answers
  • Editorial Team

    How to handle personal stress caused by utterly incompetent and ...

    • 5 Answers
  • Editorial Team

    What is a programmer’s life like?

    • 5 Answers
  • Editorial Team
    Editorial Team added an answer XNA is your friend. It's free and you write Apps… May 12, 2026 at 1:17 am
  • Editorial Team
    Editorial Team added an answer For import to find a module, it needs to either… May 12, 2026 at 1:17 am
  • Editorial Team
    Editorial Team added an answer Perhaps FSDB (file system data base) will suit your needs.… May 12, 2026 at 1:17 am

Related Questions

On our main data entry screen, we have an OK/Cancel dialog in the OnBeforePost
A weird bug was occurring in production which I was asked to look into.
Starting to look at my last year project now, and so I'm doing the
I have a SQL table which has a number of fields ID | Value

Trending Tags

analytics british company computer developers django employee employer english facebook french google interview javascript language life php programmer programs salary

Top Members

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.