components/openstack/cinder/files/cinder.prof_attr
author David Hollister <david.hollister@oracle.com>
Wed, 12 Oct 2016 14:01:13 -0600
changeset 7094 61352b4e5af5
parent 3998 5bd484384122
permissions -rw-r--r--
24797203 OpenStack RBAC profiles allow reading too many files 24797238 keystone RBAC and SMF should point at Apache log files 24797256 cinder RBAC and SMF should point at Apache log files 24830959 horizon RBAC and SMF should point at Apache log files

OpenStack Block Storage Management:RO::\
Manage OpenStack Cinder:\
auths=solaris.admin.edit/etc/cinder/*.conf,\
solaris.admin.edit/etc/cinder/*.ini,\
solaris.admin.edit/etc/cinder/*.json,\
solaris.smf.manage.cinder,\
solaris.smf.value.cinder;\
defaultpriv={file_dac_search}\:/var/log/cinder,\
{file_dac_read}\:/var/log/cinder/*,\
{file_dac_read}\:/var/svc/log/application-openstack-cinder-*

OpenStack Management:RO:::profiles=OpenStack Block Storage Management

cinder-volume:RO::\
Do not assign to users. \
Commands required for application/openstack/cinder/cinder-volume: