Re: rsbac in a network environment (LDAP and NFS)?

AJ Rabassa <[email protected]> Thu, 26 Sep 2013 14:04:26 -0400
Newsgroups gmane.linux.rsbac
Message-ID <CAJVNv2BLQyyJs+Bd=iFcF3PaJ8-wTJuFet+J1pk96-cYBLUnoQ@mail.gmail.com>
Thanks for the links, Javier.

The concern I have is that all authentication requests are going to use
LDAP (and Kerberos); the purpose of using LDAP (in this instance) is to
centralize user management and permissions across all servers.  If RSBAC
breaks that, I can't use it; every other service services we plan on using
has LDAP plugins.

A better, more refined question would be: *Without* altering
PAM/nsswitch.conf, how can I unify RSBAC's acl and rc policies?


On Thu, Sep 26, 2013 at 1:18 PM, Javier Juan Martínez Cabezón <
[email protected]> wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
>
>
>
>
>
> You have here more info:
>
>
> https://www.rsbac.org/documentation/rsbac_handbook/user_management?m=subuser_management
>
> and here
>
>
> https://www.rsbac.org/documentation/rsbac_handbook/configuration_basics/user_management
>
> On 26/09/13 17:44, AJ Rabassa wrote:
> > Sorry if this has been discussed before, I couldn't find the topic
> > using google on the list archives.
> >
> > I am trying to bring up a VM lab, and would like to use RSBAC for
> > role enforcement and ACLs. From the documentation, it seems to fit
> > exactly the needs I'll have, over SMACK (too few features) or
> > SELinux (too much maintenance). I have not used RSBAC yet; I'm
> > trying to get my plan together before I start installing things.
> >
> > The thing I'm trying to deal with is this:
> >
> > The lab will be using LDAP for auth, with a bunch of mutually
> > shared NFS volumes for the VMs.
> >
> > Where/how does rsbac store the RC and ACL module configurations? My
> > concern is having two VMs mount the same volume, and having two
> > different ACLs. Is there a method (or a set of methods, best
> > practices, whatever) to ensure consistent ACL enforcement across a
> > network with rsbac? If the filesystem supports ACLs, is it a
> > non-issue?
> >
> > The goals for this lab are new to me, so if it doesn't sound like I
> > know what I'm talking about, it's because I don't. If there are
> > better solutions than NFS, or LDAP, or any component, I'm open to
> > suggestions.
> >
> >
> > Thanks,
> >
> > AJ _______________________________________________ rsbac mailing
> > list [email protected] http://www.rsbac.org/mailman/listinfo/rsbac
>
>
>
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.12 (GNU/Linux)
>
> iQIcBAEBAgAGBQJSRGxUAAoJEFfmTgt/w77fAWMP/3WuDest4ZU68Iv6/rdaJxgK
> TPTkweDYXyTadNs231lAo4oCMsiyfT8bLcD7jGNdRwpSOpNYbvP/A2mtoVCpOKi2
> tgdFsZXPlpvN+xE3bI5x7KHpHrsbtCskV67uIIzsTvCWkr/+gIjFuGHvTrIM5XDd
> ayD+f4P1Jbha5nneM9BBcWdc9ZuCiR0pzz5xPvS11pYZPiEHQMSEyTgW9zsbgO4l
> tnfeeKqEsa+oNLTGWIvc+GuYB/mawlPRUqsNBWvQvHeL0ZDbnaNDqKLWGXYJ8tXm
> aRRyUfFRNZvSR2m4CZN3R8kXZAAY5S85fW1ggH1VFdH3zrUwy7zPGOfbiJ2Hr9Ve
> qFLKDbM1UYKtoqjhGfeloBp5RdQPEQwQPZS+h5Qd+COI1HgwGuZsXkyHcReIVZS0
> oFcju8OHglYnZ1ACJgEN3xktXbqYgal2PGeyJHhdoEFuk+epCFslx9+L9zrd9JDr
> RejAsaUTBUs1DO9Kf1f8gaL/NvzByUEte3RTwz393JSQaMTCBPWvYBQTqjlXr7S1
> mEW3Bx5R+5v9dQeBAl1esbc4Qrwftzz8WhISMTs0znA6coUWIFrQrUi51E18KDL7
> KoyCLHpchWoFMp5nuVrQBeUzz//dDJGmmIAxFgYsih/zogBH2jTgX42Vp+2KgZPY
> KCNMviwOWJvevpi07+M1
> =T+dR
> -----END PGP SIGNATURE-----
> _______________________________________________
> rsbac mailing list
> [email protected]
> http://www.rsbac.org/mailman/listinfo/rsbac
>