[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [Xen-users] Access Control solution for Xen?
On Wed, Dec 8, 2010 at 2:29 PM, Jonathan Tripathy <jonnyt@xxxxxxxxxxx> wrote:
> I am afraid I am looking for something much more finer-grained than that. For the same domU, I need different users in different roles to be allowed to do different things to it. I also want to set constraints on them to further restrict what can be done with a specific action. (e.g. role A can do migration but for role A the action migrate is only allowed to hosts x,y, and z) I have more demands from the access control solution, but we can start from here.
I also don't expect any solution to have all of this, but if there is something to start with, I might consider extending that.
> AFAICT, only the Enterprise Edition supports this, which is neither free nor open-source and I couldn't test it because they didn't hold on to their promise of "we will contact you in 24 hours".
> Why would it be "out of scope for access control"? You can implement access control in any layer. Access control is best done where the actual action takes place. Otherwise there are plenty of opportunities to get around it. If neither Xend nor Xen-API is restricted on the actual hypervisor, a bug in the management platform would allow you to do whatever you want with it. I also don't believe Xen is a Type-1 hypervisor, but that is irrelevant right now.
_______________________________________________ Xen-users mailing list Xen-users@xxxxxxxxxxxxxxxxxxx http://lists.xensource.com/xen-users
|
Lists.xenproject.org is hosted with RackSpace, monitoring our |