Re: rsbac in a network environment (LDAP and NFS)?
Javier Juan Martínez Cabezón <[email protected]> Thu, 26 Sep 2013 19:18:14 +0200
| Newsgroups | gmane.linux.rsbac |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 You have here more info: https://www.rsbac.org/documentation/rsbac_handbook/user_management?m=subuser_management and here https://www.rsbac.org/documentation/rsbac_handbook/configuration_basics/user_management On 26/09/13 17:44, AJ Rabassa wrote: > Sorry if this has been discussed before, I couldn't find the topic > using google on the list archives. > > I am trying to bring up a VM lab, and would like to use RSBAC for > role enforcement and ACLs. From the documentation, it seems to fit > exactly the needs I'll have, over SMACK (too few features) or > SELinux (too much maintenance). I have not used RSBAC yet; I'm > trying to get my plan together before I start installing things. > > The thing I'm trying to deal with is this: > > The lab will be using LDAP for auth, with a bunch of mutually > shared NFS volumes for the VMs. > > Where/how does rsbac store the RC and ACL module configurations? My > concern is having two VMs mount the same volume, and having two > different ACLs. Is there a method (or a set of methods, best > practices, whatever) to ensure consistent ACL enforcement across a > network with rsbac? If the filesystem supports ACLs, is it a > non-issue? > > The goals for this lab are new to me, so if it doesn't sound like I > know what I'm talking about, it's because I don't. If there are > better solutions than NFS, or LDAP, or any component, I'm open to > suggestions. > > > Thanks, > > AJ _______________________________________________ rsbac mailing > list [email protected] http://www.rsbac.org/mailman/listinfo/rsbac -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBAgAGBQJSRGxUAAoJEFfmTgt/w77fAWMP/3WuDest4ZU68Iv6/rdaJxgK TPTkweDYXyTadNs231lAo4oCMsiyfT8bLcD7jGNdRwpSOpNYbvP/A2mtoVCpOKi2 tgdFsZXPlpvN+xE3bI5x7KHpHrsbtCskV67uIIzsTvCWkr/+gIjFuGHvTrIM5XDd ayD+f4P1Jbha5nneM9BBcWdc9ZuCiR0pzz5xPvS11pYZPiEHQMSEyTgW9zsbgO4l tnfeeKqEsa+oNLTGWIvc+GuYB/mawlPRUqsNBWvQvHeL0ZDbnaNDqKLWGXYJ8tXm aRRyUfFRNZvSR2m4CZN3R8kXZAAY5S85fW1ggH1VFdH3zrUwy7zPGOfbiJ2Hr9Ve qFLKDbM1UYKtoqjhGfeloBp5RdQPEQwQPZS+h5Qd+COI1HgwGuZsXkyHcReIVZS0 oFcju8OHglYnZ1ACJgEN3xktXbqYgal2PGeyJHhdoEFuk+epCFslx9+L9zrd9JDr RejAsaUTBUs1DO9Kf1f8gaL/NvzByUEte3RTwz393JSQaMTCBPWvYBQTqjlXr7S1 mEW3Bx5R+5v9dQeBAl1esbc4Qrwftzz8WhISMTs0znA6coUWIFrQrUi51E18KDL7 KoyCLHpchWoFMp5nuVrQBeUzz//dDJGmmIAxFgYsih/zogBH2jTgX42Vp+2KgZPY KCNMviwOWJvevpi07+M1 =T+dR -----END PGP SIGNATURE-----