Re: rsbac in a network environment (LDAP and NFS)?
Javier Juan Martínez Cabezón <[email protected]> Thu, 26 Sep 2013 19:04:33 +0200
| Newsgroups | gmane.linux.rsbac |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, I have not experience with LDAP and NFS but if they support PAM probably you could make authentication against UM and take all benefits about module UM (as virtual users, restrict setuid to only authenticated uids, one time passwords etc etc) The data files where policies stays are stored in a directory called rsbac.dat on each filesystem. Under rsbac accessing directly to this files is heavily restricted. You can make a backup of your current policies with "backup_all -p" to be more "read-friendly". If authentication is make by uids (or virtual uids) I think there would not be problems. Since until my known each virtual user gets their own rc_def_role as a real one. On 26/09/13 17:44, AJ Rabassa wrote: > Sorry if this has been discussed before, I couldn't find the topic > using google on the list archives. > > I am trying to bring up a VM lab, and would like to use RSBAC for > role enforcement and ACLs. From the documentation, it seems to fit > exactly the needs I'll have, over SMACK (too few features) or > SELinux (too much maintenance). I have not used RSBAC yet; I'm > trying to get my plan together before I start installing things. > > The thing I'm trying to deal with is this: > > The lab will be using LDAP for auth, with a bunch of mutually > shared NFS volumes for the VMs. > > Where/how does rsbac store the RC and ACL module configurations? My > concern is having two VMs mount the same volume, and having two > different ACLs. Is there a method (or a set of methods, best > practices, whatever) to ensure consistent ACL enforcement across a > network with rsbac? If the filesystem supports ACLs, is it a > non-issue? > > The goals for this lab are new to me, so if it doesn't sound like I > know what I'm talking about, it's because I don't. If there are > better solutions than NFS, or LDAP, or any component, I'm open to > suggestions. > > > Thanks, > > AJ _______________________________________________ rsbac mailing > list [email protected] http://www.rsbac.org/mailman/listinfo/rsbac -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBAgAGBQJSRGkXAAoJEFfmTgt/w77f8CsP/0hRJ9EYTZkug3Uor/Qw3/Nr qWIR6uCmDNH34/X2iPpACk8YkIy02+gCunOwlnrtpQjGINrrPoBvKliVU/X8UmvF ozCPGkXznZZJ/gV5uB67QWErkz95AmX/Gl6FWHF2s879Lt4d7OK2JNuFgLKrnmx8 PfKGX119LYX9PjZBAdHLvhJh4q3zEOXT+5p6ZCGEUkdvLsmQaLtxfZ7XlkOZBY5v P86rfbcT4xoebdVM9EyUHYQ7y4Ue66RkwgYehkclyX91vogdvBZuaqIei2a/xStu neq0NVVEGJzQNj/7L/ha3TF8iASRy4JtnG0uvGOu1ilfbEabj0FLMaiLb4qmFnBR hBiYERhqZaLxgJzZLlPzVRcuJRbsMURbT3zKEFX5fyqXKagxSUUOwB5mBttDy6wc 1moubnhKuKR/ovsqKe2khfvui69fvDuVOn7XOagJQKwVlR3qgVRBMefvZPDW4z4Z PLqueJN02h3QizBn5+MzDtGpC6Da/PL4RTj0IlF/dqAX5jCTXwtbACxpsO+68o5Y 022dXgHUW4+X7pTOvNZNGaC//6b0LfdCc3PFP/hqGHI9RqaqsEOUpViP+oszmfLO pVNPQNf3142iNnZLf32nxYOGe6f8oXrDpWlkrqIlHgQ4HTwRb+/Bl+tsALb1CX37 EeAFGm6nYpKNy2/zzWRJ =k0T2 -----END PGP SIGNATURE-----