I would like to implement symacl in my environment but would like to get clarification on a few items.
Let's say i have a system that will need to be able to issue timefinder/clone commands. So first i create a group that consists of that system, then i create a pool that consists of devices that will be cloned and lastly i create an ACL with Rights=BCV. Let's say i have a knucklehead system admin who decides to play around with symclone command and issues "symclone restore" instead of establish. Symacl will not be able to stop him because "Rights=BCV" applies to all timefinder/clone commands ? Any way to get more granular control on timefinder operations ? ( i want to stay away from using symauth to restrict who runs the command)
First quick answer .. NO .. you have "classes" of commands .. you can not filter each and every command .. If you give "masking" (just an example) permission to an host, from this given host you will be able to add but also to REMOVE masking. I'll look further...
The code internally allows you to record each and every command your hosts issue. You can check with symaudit the "history" of your box. I think that symacl MAY be expanded to filter narrower classes of commands and/or actions for any given command (but again it is my own speculation on the subject) .. Maybe it's a good RFE for ENG .. Unfortunatly eng usually listen to customers and not to me :-P .. Maybe you can ask for such an RFE
Don't be too harsh .. the time needed to implement a given RFE depends on a number of things .. It depends on how easy is to implement .. it depends on how many requests ENG receives ..
i would like to stop the knucklehead system admin before he destroys production data. Auditing will be good for root-cause analysis ..but at that point business has suffered.
xe2sdc
6 Operator
•
2831 Posts
600
0
Posted November 13th, 2007 01:00