Just to chime in (I'm more "user" / sysadmin than developer here): I would indeed expect the group field to be filled with the data from the VOMS extension as it is provided, i.e. starting with a '/'. Space-separated if multiple groups are present sounds consistent. Summarizing, this seems to be compatible with `XrdLcmaps` and the existing VOMS plugin for the xrootd protocol. So if I see it correctly, if `xrdhttpvoms` fills the group field like that, all existing plugins would fill the group field in the same way, allowing for a common `authdb` with xrootd < 4.7. For xrootd >= 4.7, one would likely prefer to use `o` and `r` to adjust permissions in a more fine-grained manner (i.e. only atlas people / robots with production role are allowed to write to the rucio data disks). -- You are receiving this because you commented. Reply to this email directly or view it on GitHub: https://github.com/xrootd/xrootd/issues/566#issuecomment-323798600 ######################################################################## Use REPLY-ALL to reply to list To unsubscribe from the XROOTD-DEV list, click the following link: https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1