Re: HPUNIX RBAC (114 Views)
Reply
Occasional Contributor
cbecdrchennai
Posts: 3
Registered: ‎04-14-2011
Message 1 of 5 (114 Views)

HPUNIX RBAC

Hi Experts,

In our environment we have 3 different applications team with more than 10 users per team. This team requires root access to run application commands and to edit certain configuration files and directories.

Apart from ACL and sudo Is it possible this can be achieved in HPUNIX RBAC, if yes please let me know the procedure to achieve this,.

Please suggest.

Thanks in advance.
Please use plain text.
Honored Contributor
Wim Rombauts
Posts: 886
Registered: ‎08-20-1997
Message 2 of 5 (114 Views)

Re: HPUNIX RBAC

RBAC allows you to grant selected root-privileges to non-root users.
So, you can grant a group of users selective root access, but remember that this is stillroot access, meaning : There actions can severiliy impact the two other teams.

I think that what you can do with RBAC, is somewhat the same as what you can do with sudo : Allow regular users to do a few things as root. Althoug permission filtering is on another level.

Another option - if you are running HP-UX 11i v3 - is SRP. These creates some virtual subsystem within your server. You can grant root access to a team, which will only alow them to be root in there resource partition.

SRP comes very close to virtualization, but het HP-UX itself is the hypervisor and you don't need to install (and manage) yet another OS to run an application. You run the application directly on the hypervisor : HP-UX.
Please use plain text.
Outstanding Contributor
Pete Randall
Posts: 16,205
Registered: ‎11-03-1996
Message 3 of 5 (114 Views)

Re: HPUNIX RBAC

What application commands have to be run as root? And why can't any necessary configuration files and directories be handled with regular permissions? Without limited knowledge about what you're trying to accomplish, I would have to say that you need to take a long hard look at your requirements and how things are implemented.


Pete

Pete
Please use plain text.
Honored Contributor
Emil Velez
Posts: 1,450
Registered: ‎05-17-2000
Message 4 of 5 (114 Views)

Re: HPUNIX RBAC

enclosed is a example

Please use plain text.
Occasional Contributor
cbecdrchennai
Posts: 3
Registered: ‎04-14-2011
Message 5 of 5 (114 Views)

Re: HPUNIX RBAC

Thanks for the information provided.
Please use plain text.
The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the Terms of Use and Rules of Participation