Re: rsbac in a network environment (LDAP and NFS)?
AJ Rabassa <[email protected]> Thu, 26 Sep 2013 14:04:26 -0400
| Newsgroups | gmane.linux.rsbac |
|---|---|
| Message-ID | <CAJVNv2BLQyyJs+Bd=iFcF3PaJ8-wTJuFet+J1pk96-cYBLUnoQ@mail.gmail.com> |
Thanks for the links, Javier. The concern I have is that all authentication requests are going to use LDAP (and Kerberos); the purpose of using LDAP (in this instance) is to centralize user management and permissions across all servers. If RSBAC breaks that, I can't use it; every other service services we plan on using has LDAP plugins. A better, more refined question would be: *Without* altering PAM/nsswitch.conf, how can I unify RSBAC's acl and rc policies? On Thu, Sep 26, 2013 at 1:18 PM, Javier Juan Martínez Cabezón < [email protected]> wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > > > > You have here more info: > > > https://www.rsbac.org/documentation/rsbac_handbook/user_management?m=subuser_management > > and here > > > https://www.rsbac.org/documentation/rsbac_handbook/configuration_basics/user_management > > On 26/09/13 17:44, AJ Rabassa wrote: > > Sorry if this has been discussed before, I couldn't find the topic > > using google on the list archives. > > > > I am trying to bring up a VM lab, and would like to use RSBAC for > > role enforcement and ACLs. From the documentation, it seems to fit > > exactly the needs I'll have, over SMACK (too few features) or > > SELinux (too much maintenance). I have not used RSBAC yet; I'm > > trying to get my plan together before I start installing things. > > > > The thing I'm trying to deal with is this: > > > > The lab will be using LDAP for auth, with a bunch of mutually > > shared NFS volumes for the VMs. > > > > Where/how does rsbac store the RC and ACL module configurations? My > > concern is having two VMs mount the same volume, and having two > > different ACLs. Is there a method (or a set of methods, best > > practices, whatever) to ensure consistent ACL enforcement across a > > network with rsbac? If the filesystem supports ACLs, is it a > > non-issue? > > > > The goals for this lab are new to me, so if it doesn't sound like I > > know what I'm talking about, it's because I don't. If there are > > better solutions than NFS, or LDAP, or any component, I'm open to > > suggestions. > > > > > > Thanks, > > > > AJ _______________________________________________ rsbac mailing > > list [email protected] http://www.rsbac.org/mailman/listinfo/rsbac > > > > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.12 (GNU/Linux) > > iQIcBAEBAgAGBQJSRGxUAAoJEFfmTgt/w77fAWMP/3WuDest4ZU68Iv6/rdaJxgK > TPTkweDYXyTadNs231lAo4oCMsiyfT8bLcD7jGNdRwpSOpNYbvP/A2mtoVCpOKi2 > tgdFsZXPlpvN+xE3bI5x7KHpHrsbtCskV67uIIzsTvCWkr/+gIjFuGHvTrIM5XDd > ayD+f4P1Jbha5nneM9BBcWdc9ZuCiR0pzz5xPvS11pYZPiEHQMSEyTgW9zsbgO4l > tnfeeKqEsa+oNLTGWIvc+GuYB/mawlPRUqsNBWvQvHeL0ZDbnaNDqKLWGXYJ8tXm > aRRyUfFRNZvSR2m4CZN3R8kXZAAY5S85fW1ggH1VFdH3zrUwy7zPGOfbiJ2Hr9Ve > qFLKDbM1UYKtoqjhGfeloBp5RdQPEQwQPZS+h5Qd+COI1HgwGuZsXkyHcReIVZS0 > oFcju8OHglYnZ1ACJgEN3xktXbqYgal2PGeyJHhdoEFuk+epCFslx9+L9zrd9JDr > RejAsaUTBUs1DO9Kf1f8gaL/NvzByUEte3RTwz393JSQaMTCBPWvYBQTqjlXr7S1 > mEW3Bx5R+5v9dQeBAl1esbc4Qrwftzz8WhISMTs0znA6coUWIFrQrUi51E18KDL7 > KoyCLHpchWoFMp5nuVrQBeUzz//dDJGmmIAxFgYsih/zogBH2jTgX42Vp+2KgZPY > KCNMviwOWJvevpi07+M1 > =T+dR > -----END PGP SIGNATURE----- > _______________________________________________ > rsbac mailing list > [email protected] > http://www.rsbac.org/mailman/listinfo/rsbac >