As per OpenAFS Security Advisory 2007-01, setuid status has been disabled on all of the core managed servers and workstations. This has been done via a cfengine change, and the introduction of an init script which will disable setuid status on bootup.