rsbac in a network environment (LDAP and NFS)?

AJ Rabassa <[email protected]> Thu, 26 Sep 2013 11:44:14 -0400
Newsgroups gmane.linux.rsbac
Message-ID <CAJVNv2Ca1Yix_OgYadPf72C=YHPEKVRC9PGQsOJm2tnSpEyYXA@mail.gmail.com>
Sorry if this has been discussed before, I couldn't find the topic using
google on the list archives.

I am trying to bring up a VM lab, and would like to use RSBAC for role
enforcement and ACLs. From the documentation, it seems to fit exactly the
needs I'll have, over SMACK (too few features) or SELinux (too much
maintenance). I have not used RSBAC yet; I'm trying to get my plan together
before I start installing things.

The thing I'm trying to deal with is this:

The lab will be using LDAP for auth, with a bunch of mutually shared NFS
volumes for the VMs.

Where/how does rsbac store the RC and ACL module configurations? My concern
is having two VMs mount the same volume, and having two different ACLs. Is
there a method (or a set of methods, best practices, whatever) to ensure
consistent ACL enforcement across a network with rsbac? If the filesystem
supports ACLs, is it a non-issue?

The goals for this lab are new to me, so if it doesn't sound like I know
what I'm talking about, it's because I don't. If there are better solutions
than NFS, or LDAP, or any component, I'm open to suggestions.


Thanks,

AJ