Re: [Pacemaker] Multi-level ACLs for the CIB

2010-03-18 Thread Yan Gao
On 03/19/10 06:22, Lars Ellenberg wrote: > On Wed, Mar 17, 2010 at 06:12:24PM +0800, Yan Gao wrote: >> After investigating, I found that Unix domain sockets provide methods to >> identify the user on the other side of a socket. That means we don't need >> PAM to do authentication for local access,

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-03-18 Thread Lars Ellenberg
On Wed, Mar 17, 2010 at 06:12:24PM +0800, Yan Gao wrote: > After investigating, I found that Unix domain sockets provide methods to > identify the user on the other side of a socket. That means we don't need > PAM to do authentication for local access, and the clients doesn't need > to prompt user

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-03-18 Thread Yan Gao
On 03/18/10 22:54, Yan Gao wrote: > On 03/18/10 21:00, Andrew Beekhof wrote: >> On Thu, Mar 18, 2010 at 12:29 PM, Dejan Muhamedagic >> wrote: >>> Hi, >>> >>> On Thu, Mar 18, 2010 at 11:30:10AM +0100, Andrew Beekhof wrote: On Thu, Mar 18, 2010 at 11:10 AM, Yan Gao wrote: > > > On

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-03-18 Thread Dejan Muhamedagic
On Thu, Mar 18, 2010 at 02:00:04PM +0100, Andrew Beekhof wrote: > On Thu, Mar 18, 2010 at 12:29 PM, Dejan Muhamedagic > wrote: > > Hi, > > > > On Thu, Mar 18, 2010 at 11:30:10AM +0100, Andrew Beekhof wrote: > >> On Thu, Mar 18, 2010 at 11:10 AM, Yan Gao wrote: > >> > > >> > > >> > On 03/18/10 17

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-03-18 Thread Yan Gao
On 03/18/10 21:00, Andrew Beekhof wrote: > On Thu, Mar 18, 2010 at 12:29 PM, Dejan Muhamedagic > wrote: >> Hi, >> >> On Thu, Mar 18, 2010 at 11:30:10AM +0100, Andrew Beekhof wrote: >>> On Thu, Mar 18, 2010 at 11:10 AM, Yan Gao wrote: On 03/18/10 17:11, Andrew Beekhof wrote: >

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-03-18 Thread Andrew Beekhof
On Thu, Mar 18, 2010 at 12:29 PM, Dejan Muhamedagic wrote: > Hi, > > On Thu, Mar 18, 2010 at 11:30:10AM +0100, Andrew Beekhof wrote: >> On Thu, Mar 18, 2010 at 11:10 AM, Yan Gao wrote: >> > >> > >> > On 03/18/10 17:11, Andrew Beekhof wrote: >> >> On Thu, Mar 18, 2010 at 9:53 AM, Yan Gao wrote: >

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-03-18 Thread Dejan Muhamedagic
Hi, On Thu, Mar 18, 2010 at 07:49:04PM +0800, Yan Gao wrote: > Hi Dejan, > > On 03/18/10 19:23, Dejan Muhamedagic wrote: > > Hi Yan, > > > > On Wed, Mar 17, 2010 at 06:12:24PM +0800, Yan Gao wrote: > >> Hi Andrew, > >> > >> On 02/23/10 17:23, Yan Gao wrote: > >>> On 02/23/10 04:10, Andrew Beekho

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-03-18 Thread Yan Gao
Hi Dejan, On 03/18/10 19:23, Dejan Muhamedagic wrote: > Hi Yan, > > On Wed, Mar 17, 2010 at 06:12:24PM +0800, Yan Gao wrote: >> Hi Andrew, >> >> On 02/23/10 17:23, Yan Gao wrote: >>> On 02/23/10 04:10, Andrew Beekhof wrote: On Mon, Feb 22, 2010 at 8:58 AM, Yan Gao wrote: > Hi Andrew, >>

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-03-18 Thread Yan Gao
On 03/18/10 18:30, Andrew Beekhof wrote: > On Thu, Mar 18, 2010 at 11:10 AM, Yan Gao wrote: >> >> >> On 03/18/10 17:11, Andrew Beekhof wrote: >>> On Thu, Mar 18, 2010 at 9:53 AM, Yan Gao wrote: On 03/18/10 16:33, Andrew Beekhof wrote: > On Wed, Mar 17, 2010 at 11:12 AM, Yan Gao wrote:

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-03-18 Thread Dejan Muhamedagic
Hi, On Thu, Mar 18, 2010 at 11:30:10AM +0100, Andrew Beekhof wrote: > On Thu, Mar 18, 2010 at 11:10 AM, Yan Gao wrote: > > > > > > On 03/18/10 17:11, Andrew Beekhof wrote: > >> On Thu, Mar 18, 2010 at 9:53 AM, Yan Gao wrote: > >>> On 03/18/10 16:33, Andrew Beekhof wrote: > On Wed, Mar 17, 2

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-03-18 Thread Dejan Muhamedagic
Hi Yan, On Wed, Mar 17, 2010 at 06:12:24PM +0800, Yan Gao wrote: > Hi Andrew, > > On 02/23/10 17:23, Yan Gao wrote: > > On 02/23/10 04:10, Andrew Beekhof wrote: > >> On Mon, Feb 22, 2010 at 8:58 AM, Yan Gao wrote: > >>> Hi Andrew, > >>> > >>> On 02/08/10 17:48, Andrew Beekhof wrote: > On Th

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-03-18 Thread Andrew Beekhof
On Thu, Mar 18, 2010 at 11:10 AM, Yan Gao wrote: > > > On 03/18/10 17:11, Andrew Beekhof wrote: >> On Thu, Mar 18, 2010 at 9:53 AM, Yan Gao wrote: >>> On 03/18/10 16:33, Andrew Beekhof wrote: On Wed, Mar 17, 2010 at 11:12 AM, Yan Gao wrote: > Hi Andrew, > > On 02/23/10 17:23, Ya

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-03-18 Thread Yan Gao
On 03/18/10 17:11, Andrew Beekhof wrote: > On Thu, Mar 18, 2010 at 9:53 AM, Yan Gao wrote: >> On 03/18/10 16:33, Andrew Beekhof wrote: >>> On Wed, Mar 17, 2010 at 11:12 AM, Yan Gao wrote: Hi Andrew, On 02/23/10 17:23, Yan Gao wrote: > On 02/23/10 04:10, Andrew Beekhof wrote:

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-03-18 Thread Andrew Beekhof
On Thu, Mar 18, 2010 at 9:53 AM, Yan Gao wrote: > On 03/18/10 16:33, Andrew Beekhof wrote: >> On Wed, Mar 17, 2010 at 11:12 AM, Yan Gao wrote: >>> Hi Andrew, >>> >>> On 02/23/10 17:23, Yan Gao wrote: On 02/23/10 04:10, Andrew Beekhof wrote: > On Mon, Feb 22, 2010 at 8:58 AM, Yan Gao wro

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-03-18 Thread Yan Gao
On 03/18/10 16:33, Andrew Beekhof wrote: > On Wed, Mar 17, 2010 at 11:12 AM, Yan Gao wrote: >> Hi Andrew, >> >> On 02/23/10 17:23, Yan Gao wrote: >>> On 02/23/10 04:10, Andrew Beekhof wrote: On Mon, Feb 22, 2010 at 8:58 AM, Yan Gao wrote: > Hi Andrew, > > On 02/08/10 17:48, Andre

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-03-18 Thread Andrew Beekhof
On Wed, Mar 17, 2010 at 11:12 AM, Yan Gao wrote: > Hi Andrew, > > On 02/23/10 17:23, Yan Gao wrote: >> On 02/23/10 04:10, Andrew Beekhof wrote: >>> On Mon, Feb 22, 2010 at 8:58 AM, Yan Gao wrote: Hi Andrew, On 02/08/10 17:48, Andrew Beekhof wrote: > On Thu, Feb 4, 2010 at 5:24

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-03-17 Thread Yan Gao
Hi Andrew, On 02/23/10 17:23, Yan Gao wrote: > On 02/23/10 04:10, Andrew Beekhof wrote: >> On Mon, Feb 22, 2010 at 8:58 AM, Yan Gao wrote: >>> Hi Andrew, >>> >>> On 02/08/10 17:48, Andrew Beekhof wrote: On Thu, Feb 4, 2010 at 5:24 PM, Yan Gao wrote: >> And put exclusions for things like

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-02-23 Thread Yan Gao
On 02/23/10 04:10, Andrew Beekhof wrote: > On Mon, Feb 22, 2010 at 8:58 AM, Yan Gao wrote: >> Hi Andrew, >> >> On 02/08/10 17:48, Andrew Beekhof wrote: >>> On Thu, Feb 4, 2010 at 5:24 PM, Yan Gao wrote: > And put exclusions for things like passwords before the read for the > whole cib?

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-02-22 Thread Andrew Beekhof
On Mon, Feb 22, 2010 at 8:58 AM, Yan Gao wrote: > Hi Andrew, > > On 02/08/10 17:48, Andrew Beekhof wrote: >> On Thu, Feb 4, 2010 at 5:24 PM, Yan Gao wrote: And put exclusions for things like passwords before  the read for the whole cib? >>> Yes. We should specify any "deny" and "write"

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-02-22 Thread Yan Gao
Hi Andrew, On 02/08/10 17:48, Andrew Beekhof wrote: > On Thu, Feb 4, 2010 at 5:24 PM, Yan Gao wrote: >>> And put exclusions for things like passwords before the read for the whole >>> cib? >> Yes. We should specify any "deny" and "write" objects before it. > > I like the syntax now, but my ori

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-02-08 Thread Andrew Beekhof
On Thu, Feb 4, 2010 at 5:24 PM, Yan Gao wrote: >> And put exclusions for things like passwords before  the read for the whole >> cib? > Yes. We should specify any "deny" and "write" objects before it. I like the syntax now, but my original concern (that all the validation occurs in the client li

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-02-04 Thread Yan Gao
On 02/04/10 21:01, Andrew Beekhof wrote: > On Thu, Feb 4, 2010 at 8:51 AM, Yan Gao wrote: >> >> >> On 02/04/10 15:15, Andrew Beekhof wrote: >>> On Thu, Feb 4, 2010 at 4:52 AM, Yan Gao wrote: Andrew Beekhof wrote: > On Tue, Feb 2, 2010 at 6:14 AM, Yan Gao wrote: > > [s

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-02-04 Thread Andrew Beekhof
On Thu, Feb 4, 2010 at 8:51 AM, Yan Gao wrote: > > > On 02/04/10 15:15, Andrew Beekhof wrote: >> On Thu, Feb 4, 2010 at 4:52 AM, Yan Gao wrote: >>> >>> >>> Andrew Beekhof wrote: On Tue, Feb 2, 2010 at 6:14 AM, Yan Gao wrote: [snip] > A configuration example: > ..

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-02-03 Thread Yan Gao
On 02/04/10 15:15, Andrew Beekhof wrote: > On Thu, Feb 4, 2010 at 4:52 AM, Yan Gao wrote: >> >> >> Andrew Beekhof wrote: >>> On Tue, Feb 2, 2010 at 6:14 AM, Yan Gao wrote: >>> >>> [snip] >>> A configuration example: .. >>>

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-02-03 Thread Andrew Beekhof
On Thu, Feb 4, 2010 at 4:52 AM, Yan Gao wrote: > > > Andrew Beekhof wrote: >> On Tue, Feb 2, 2010 at 6:14 AM, Yan Gao wrote: >> >> [snip] >> >>> A configuration example: >>> .. >>> >>>   >>>     >>>     >>>   >>>   >>>     >>>     >>>   >> >> [snip] >> >> Quick question, have you tried using crm

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-02-03 Thread Yan Gao
On 02/04/10 12:36, Tim Serong wrote: > On 2/4/2010 at 02:52 PM, Yan Gao wrote: >> >> Andrew Beekhof wrote: >>> On Tue, Feb 2, 2010 at 6:14 AM, Yan Gao wrote: >>> >>> [snip] >>> A configuration example: ..

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-02-03 Thread Tim Serong
On 2/4/2010 at 02:52 PM, Yan Gao wrote: > > Andrew Beekhof wrote: > > On Tue, Feb 2, 2010 at 6:14 AM, Yan Gao wrote: > > > > [snip] > > > >> A configuration example: > >> .. > >> > >> > >> > >> > >> > >> > >> > >> > >> > > > > [snip] > > > > Quic

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-02-03 Thread Yan Gao
Andrew Beekhof wrote: > On Tue, Feb 2, 2010 at 6:14 AM, Yan Gao wrote: > > [snip] > >> A configuration example: >> .. >> >> >> >> >> >> >> >> >> > > [snip] > > Quick question, have you tried using crm_mon with a configuration like this? > I'm pretty sure you'll get n

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-02-03 Thread Andrew Beekhof
On Tue, Feb 2, 2010 at 6:14 AM, Yan Gao wrote: [snip] > A configuration example: > .. > >   >     >     >   >   >     >     >   [snip] Quick question, have you tried using crm_mon with a configuration like this? I'm pretty sure you'll get nothing sensible as it can't find the resources. Migh

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-02-01 Thread Yan Gao
Hi, Sorry for delaying this update so long because of some other works. The ACL implementation has been improved. As we discussed, two new functionalities has been added: * The access control on attributes of elements * xpath based ACL. The schema and the corresponding codes has been simplified:

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-14 Thread Andrew Beekhof
On Wed, Jan 13, 2010 at 11:07 AM, Dejan Muhamedagic wrote: > Hi, > > On Wed, Jan 13, 2010 at 10:04:12AM +0100, Andrew Beekhof wrote: > [...] >> I don't think you want that. >> "One user, one role" would be my advice. > > Wouldn't that be too restrictive? I don't see why. It just requires the adm

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-13 Thread Yan Gao
Hi, Dejan Muhamedagic wrote: > Hi Yan, > > On Wed, Jan 13, 2010 at 08:49:00PM +0800, Yan Gao wrote: >> Dejan Muhamedagic wrote: >>> Hi, >>> >>> On Wed, Jan 13, 2010 at 10:04:12AM +0100, Andrew Beekhof wrote: >>> [...] > The user "ygao" is a system account. > We could define severa

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-13 Thread Dejan Muhamedagic
Hi Yan, On Wed, Jan 13, 2010 at 08:49:00PM +0800, Yan Gao wrote: > Dejan Muhamedagic wrote: > > Hi, > > > > On Wed, Jan 13, 2010 at 10:04:12AM +0100, Andrew Beekhof wrote: > > [...] > >>> The user "ygao" is a system account. > >>> We could define several roles as we wish, such as "admin",

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-13 Thread Yan Gao
Dejan Muhamedagic wrote: > Hi, > > On Wed, Jan 13, 2010 at 10:04:12AM +0100, Andrew Beekhof wrote: > [...] >>> The user "ygao" is a system account. >>> We could define several roles as we wish, such as "admin", >>> "operator" and "monitor", which could contain a member list >>> res

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-13 Thread Yan Gao
Hi Dejan, Dejan Muhamedagic wrote: > Hi Yan, > > On Wed, Jan 13, 2010 at 01:21:29PM +0800, Yan Gao wrote: >> Dejan Muhamedagic wrote: >>> Hi, >>> >>> On Tue, Jan 12, 2010 at 08:00:56PM +0800, Yan Gao wrote: Hi Dejan, Dejan Muhamedagic wrote: > Hi, > > On Mon, Jan 11, 20

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-13 Thread Yan Gao
Andrew Beekhof wrote: > On Wed, Jan 13, 2010 at 6:21 AM, Yan Gao wrote: >> Dejan Muhamedagic wrote: >>> Hi, >>> >>> On Tue, Jan 12, 2010 at 08:00:56PM +0800, Yan Gao wrote: Hi Dejan, Dejan Muhamedagic wrote: >> The user "ygao" is a system account. >> We could define several

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-13 Thread Yan Gao
Andrew Beekhof wrote: > On Tue, Jan 12, 2010 at 1:06 PM, Yan Gao wrote: >> Andrew Beekhof wrote: >>> On Tue, Jan 12, 2010 at 10:41 AM, Dejan Muhamedagic >>> wrote: Hi, On Mon, Jan 11, 2010 at 09:01:30PM +0800, Yan Gao wrote: > BTW, there're some changes comparing to the origin

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-13 Thread Dejan Muhamedagic
Hi, On Wed, Jan 13, 2010 at 10:04:12AM +0100, Andrew Beekhof wrote: [...] > > The user "ygao" is a system account. > > We could define several roles as we wish, such as "admin", > > "operator" and "monitor", which could contain a member list > > respectively if more than one user h

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-13 Thread Dejan Muhamedagic
Hi Yan, On Wed, Jan 13, 2010 at 01:21:29PM +0800, Yan Gao wrote: > Dejan Muhamedagic wrote: > > Hi, > > > > On Tue, Jan 12, 2010 at 08:00:56PM +0800, Yan Gao wrote: > >> Hi Dejan, > >> > >> Dejan Muhamedagic wrote: > >>> Hi, > >>> > >>> On Mon, Jan 11, 2010 at 09:01:30PM +0800, Yan Gao wrote: > >

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-13 Thread Andrew Beekhof
On Wed, Jan 13, 2010 at 6:21 AM, Yan Gao wrote: > Dejan Muhamedagic wrote: >> Hi, >> >> On Tue, Jan 12, 2010 at 08:00:56PM +0800, Yan Gao wrote: >>> Hi Dejan, >>> >>> Dejan Muhamedagic wrote: Hi, On Mon, Jan 11, 2010 at 09:01:30PM +0800, Yan Gao wrote: > .. >     >    

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-13 Thread Andrew Beekhof
On Tue, Jan 12, 2010 at 1:06 PM, Yan Gao wrote: > > Andrew Beekhof wrote: >> On Tue, Jan 12, 2010 at 10:41 AM, Dejan Muhamedagic >> wrote: >>> Hi, >>> >>> On Mon, Jan 11, 2010 at 09:01:30PM +0800, Yan Gao wrote: >> >> Ah, I was looking in the patch. >>                    

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-12 Thread Yan Gao
Dejan Muhamedagic wrote: > Hi, > > On Tue, Jan 12, 2010 at 08:00:56PM +0800, Yan Gao wrote: >> Hi Dejan, >> >> Dejan Muhamedagic wrote: >>> Hi, >>> >>> On Mon, Jan 11, 2010 at 09:01:30PM +0800, Yan Gao wrote: ..

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-12 Thread Dejan Muhamedagic
Hi, On Tue, Jan 12, 2010 at 08:00:56PM +0800, Yan Gao wrote: > Hi Dejan, > > Dejan Muhamedagic wrote: > > Hi, > > > > On Mon, Jan 11, 2010 at 09:01:30PM +0800, Yan Gao wrote: > >> .. > >> > >> > >> > >> > >> > >> > >> > >> > >>

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-12 Thread Yan Gao
Andrew Beekhof wrote: > On Tue, Jan 12, 2010 at 10:41 AM, Dejan Muhamedagic > wrote: >> Hi, >> >> On Mon, Jan 11, 2010 at 09:01:30PM +0800, Yan Gao wrote: > > Ah, I was looking in the patch. > >>> >>> >>> >>> >>> >>> >>> >>> >>>

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-12 Thread Yan Gao
Hi Dejan, Dejan Muhamedagic wrote: > Hi, > > On Mon, Jan 11, 2010 at 09:01:30PM +0800, Yan Gao wrote: >> .. >> >> >> >> >> >> >> >> >> >> >> >> >> >> >> >> >> >

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-12 Thread Andrew Beekhof
On Tue, Jan 12, 2010 at 10:41 AM, Dejan Muhamedagic wrote: > Hi, > > On Mon, Jan 11, 2010 at 09:01:30PM +0800, Yan Gao wrote: Ah, I was looking in the patch. >>     >>       >>         >>         >>       >>       >>         >>         >>       >>       >>         >>         >>      

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-12 Thread Dejan Muhamedagic
Hi, On Mon, Jan 11, 2010 at 09:01:30PM +0800, Yan Gao wrote: > .. > > > > > > > > > > > > > > > > > > > I understand that the "ref" element re

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-12 Thread Andrew Beekhof
On Tue, Jan 12, 2010 at 9:53 AM, Yan Gao wrote: > Hi Andrew, > > Andrew Beekhof wrote: >> On Mon, Jan 11, 2010 at 4:08 PM, Lars Marowsky-Bree wrote: >>> In the mean-time, reviewing the syntax is probably quite important too. >> >> Has it changed since we discussed it last? > Yes, it has changed a

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-12 Thread Yan Gao
Hi Andrew, Andrew Beekhof wrote: > On Mon, Jan 11, 2010 at 4:08 PM, Lars Marowsky-Bree wrote: >> In the mean-time, reviewing the syntax is probably quite important too. > > Has it changed since we discussed it last? Yes, it has changed a bit comparing to the original design. > I don't see any n

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-12 Thread Andrew Beekhof
On Mon, Jan 11, 2010 at 4:08 PM, Lars Marowsky-Bree wrote: > In the mean-time, reviewing the syntax is probably quite important too. Has it changed since we discussed it last? I don't see any new examples to comment on. ___ Pacemaker mailing list Pacem

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-12 Thread Yan Gao
Hi Lars, Lars Marowsky-Bree wrote: > On 2010-01-11T15:02:29, Andrew Beekhof wrote: > >>> For this authentication issue of local access we discussed last time, I >>> added a geteuid() in the cib_native_signon_raw() function from libcib. >>> Once a client signs on the CIB, it'll invoke the functio

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-12 Thread Yan Gao
Hi Andrew, Andrew Beekhof wrote: > On Mon, Jan 11, 2010 at 2:01 PM, Yan Gao wrote: >> Hi all, Andrew, Lars, >> >> Here's the status update about this feature. >> >> I've implemented the main functionalities of ACL, including the ACLs >> configuration parser, the CIB output filter and the modifica

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-11 Thread Lars Marowsky-Bree
On 2010-01-11T15:02:29, Andrew Beekhof wrote: > > For this authentication issue of local access we discussed last time, I > > added a geteuid() in the cib_native_signon_raw() function from libcib. > > Once a client signs on the CIB, it'll invoke the function and transfer > > its uid to the server

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-11 Thread Andrew Beekhof
On Mon, Jan 11, 2010 at 2:01 PM, Yan Gao wrote: > Hi all, Andrew, Lars, > > Here's the status update about this feature. > > I've implemented the main functionalities of ACL, including the ACLs > configuration parser, the CIB output filter and the modification checker... > > Yan Gao wrote: >> On 1

Re: [Pacemaker] Multi-level ACLs for the CIB

2010-01-11 Thread Yan Gao
Hi all, Andrew, Lars, Here's the status update about this feature. I've implemented the main functionalities of ACL, including the ACLs configuration parser, the CIB output filter and the modification checker... Yan Gao wrote: > On 12/09/09 18:28, Andrew Beekhof wrote: >> On Wed, Dec 9, 2009 at

Re: [Pacemaker] Multi-level ACLs for the CIB

2009-12-10 Thread Yan Gao
On 12/09/09 18:28, Andrew Beekhof wrote: > On Wed, Dec 9, 2009 at 11:00 AM, Yan Gao wrote: >> Hi Andrew, Lars, >> >> On 12/08/09 21:16, Lars Marowsky-Bree wrote: >>> On 2009-12-08T09:22:52, Andrew Beekhof wrote: >>> > Basically, we'd like to see an ACL mechanism. It would be implemented at >>

Re: [Pacemaker] Multi-level ACLs for the CIB

2009-12-09 Thread Andrew Beekhof
On Wed, Dec 9, 2009 at 11:00 AM, Yan Gao wrote: > Hi Andrew, Lars, > > On 12/08/09 21:16, Lars Marowsky-Bree wrote: >> On 2009-12-08T09:22:52, Andrew Beekhof wrote: >> Basically, we'd like to see an ACL mechanism. It would be implemented at the CIB level. So that all the clients - CLI ,

Re: [Pacemaker] Multi-level ACLs for the CIB

2009-12-09 Thread Yan Gao
Hi Andrew, Lars, On 12/08/09 21:16, Lars Marowsky-Bree wrote: > On 2009-12-08T09:22:52, Andrew Beekhof wrote: > >>> Basically, we'd like to see an ACL mechanism. It would be implemented at >>> the CIB level. So that all the clients - CLI , CRM shell, GUI, etc... - >>> could benefit. Clients are

Re: [Pacemaker] Multi-level ACLs for the CIB

2009-12-09 Thread Andrew Beekhof
On Tue, Dec 8, 2009 at 2:16 PM, Lars Marowsky-Bree wrote: > On 2009-12-08T09:22:52, Andrew Beekhof wrote: > >> > Basically, we'd like to see an ACL mechanism. It would be implemented at >> > the CIB level. So that all the clients - CLI , CRM shell, GUI, etc... - >> > could benefit. Clients are au

Re: [Pacemaker] Multi-level ACLs for the CIB

2009-12-08 Thread Lars Marowsky-Bree
On 2009-12-08T09:22:52, Andrew Beekhof wrote: > > Basically, we'd like to see an ACL mechanism. It would be implemented at > > the CIB level. So that all the clients - CLI , CRM shell, GUI, etc... - > > could benefit. Clients are authenticated via PAM, so we can use uid/gid > > for identification

Re: [Pacemaker] Multi-level ACLs for the CIB

2009-12-08 Thread Andrew Beekhof
On Mon, Dec 7, 2009 at 9:06 AM, Yan Gao wrote: > Hi all, Andrew, > > This planned feature was proposed by Lars. After some discussions > with Lars and Tim, I'm sharing it here, and looking forward to hearing > your thoughts and suggestions. > > The goal of this feature is to provide different leve

[Pacemaker] Multi-level ACLs for the CIB

2009-12-07 Thread Yan Gao
Hi all, Andrew, This planned feature was proposed by Lars. After some discussions with Lars and Tim, I'm sharing it here, and looking forward to hearing your thoughts and suggestions. The goal of this feature is to provide different levels of administration to users. Some of the common scenarios