Re: rsbac in a network environment (LDAP and NFS)?

Javier Juan Martínez Cabezón <[email protected]> Thu, 26 Sep 2013 19:04:33 +0200
Newsgroups gmane.linux.rsbac
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1




Hi, I have not experience with LDAP and NFS but if they support PAM
probably you could make authentication against UM and take all
benefits about module UM (as virtual users, restrict setuid to only
authenticated uids, one time passwords etc etc)

The data files where policies stays are stored in a directory called
rsbac.dat on each filesystem. Under rsbac accessing directly to this
files is heavily restricted. You can make a backup of your current
policies with "backup_all -p" to be more "read-friendly".

If authentication is make by uids (or virtual uids) I think there
would not be problems. Since until my known each virtual user gets
their own rc_def_role as a real one.




On 26/09/13 17:44, AJ Rabassa wrote:
> Sorry if this has been discussed before, I couldn't find the topic
> using google on the list archives.
> 
> I am trying to bring up a VM lab, and would like to use RSBAC for
> role enforcement and ACLs. From the documentation, it seems to fit
> exactly the needs I'll have, over SMACK (too few features) or
> SELinux (too much maintenance). I have not used RSBAC yet; I'm
> trying to get my plan together before I start installing things.
> 
> The thing I'm trying to deal with is this:
> 
> The lab will be using LDAP for auth, with a bunch of mutually
> shared NFS volumes for the VMs.
> 
> Where/how does rsbac store the RC and ACL module configurations? My
> concern is having two VMs mount the same volume, and having two
> different ACLs. Is there a method (or a set of methods, best
> practices, whatever) to ensure consistent ACL enforcement across a
> network with rsbac? If the filesystem supports ACLs, is it a
> non-issue?
> 
> The goals for this lab are new to me, so if it doesn't sound like I
> know what I'm talking about, it's because I don't. If there are
> better solutions than NFS, or LDAP, or any component, I'm open to
> suggestions.
> 
> 
> Thanks,
> 
> AJ _______________________________________________ rsbac mailing
> list [email protected] http://www.rsbac.org/mailman/listinfo/rsbac

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBAgAGBQJSRGkXAAoJEFfmTgt/w77f8CsP/0hRJ9EYTZkug3Uor/Qw3/Nr
qWIR6uCmDNH34/X2iPpACk8YkIy02+gCunOwlnrtpQjGINrrPoBvKliVU/X8UmvF
ozCPGkXznZZJ/gV5uB67QWErkz95AmX/Gl6FWHF2s879Lt4d7OK2JNuFgLKrnmx8
PfKGX119LYX9PjZBAdHLvhJh4q3zEOXT+5p6ZCGEUkdvLsmQaLtxfZ7XlkOZBY5v
P86rfbcT4xoebdVM9EyUHYQ7y4Ue66RkwgYehkclyX91vogdvBZuaqIei2a/xStu
neq0NVVEGJzQNj/7L/ha3TF8iASRy4JtnG0uvGOu1ilfbEabj0FLMaiLb4qmFnBR
hBiYERhqZaLxgJzZLlPzVRcuJRbsMURbT3zKEFX5fyqXKagxSUUOwB5mBttDy6wc
1moubnhKuKR/ovsqKe2khfvui69fvDuVOn7XOagJQKwVlR3qgVRBMefvZPDW4z4Z
PLqueJN02h3QizBn5+MzDtGpC6Da/PL4RTj0IlF/dqAX5jCTXwtbACxpsO+68o5Y
022dXgHUW4+X7pTOvNZNGaC//6b0LfdCc3PFP/hqGHI9RqaqsEOUpViP+oszmfLO
pVNPQNf3142iNnZLf32nxYOGe6f8oXrDpWlkrqIlHgQ4HTwRb+/Bl+tsALb1CX37
EeAFGm6nYpKNy2/zzWRJ
=k0T2
-----END PGP SIGNATURE-----