Re: [one-users] users can see other VMs, security concern ?

2011-02-25 Thread Danny Sternkopf
Yep, it is definately a major security risk. The sunstone WebGUI has a user limited view in contrast. On 2011-02-25 15:58, Zeeshan Ali Shah wrote: wow, i think user can see each other VM , definately they cannot delete them , but they can even look into other vms with onevm show.. is it

Re: [one-users] users can see other VMs, security concern ?

2011-02-25 Thread Zeeshan Ali Shah
i think sunstone is not release yet ? how to get source of it .. it only shows screenshot here. http://blog.opennebula.org/?p=1344 On 02/25/2011 03:01 PM, Danny Sternkopf wrote: Yep, it is definately a major security risk. The sunstone WebGUI has a user limited view in contrast. On

Re: [one-users] users can see other VMs, security concern ?

2011-02-25 Thread Tino Vazquez
Hi Zeeshan, Danny, Sunstone in its current version (coming really soon ;) ) is not a public cloud interface, but rather a private cloud interface. In the future, we plan to add role support, so you can have different views depending on the user. Internal users (private cloud users) can see the

Re: [one-users] users can see other VMs, security concern ?

2011-02-25 Thread Zeeshan Ali Shah
Hi Tino, I think there is a slight confusion of Private/Public .. I mean Private cloud is for Private user such as your employee etc. (not for walking customer) . so in this scenario one user shd not see other user's vm . or even scan whole of infrastructure. for user in linux in case of