Re: Idea for multi-level CLI access control

2023-06-27 Thread Dridi Boukelmoune
On Tue, Jun 27, 2023 at 9:24 AM Poul-Henning Kamp wrote: > > > Dridi Boukelmoune writes: > > On Mon, Jun 26, 2023 at 6:39=E2=80=AFPM Poul-Henning Kamp > dk> wrote: > > > > > > Regarding the specific suggestion above, I don't think we would be > > satisfied with this model. In the securit

Re: Idea for multi-level CLI access control

2023-06-27 Thread Poul-Henning Kamp
Dridi Boukelmoune writes: > On Mon, Jun 26, 2023 at 6:39=E2=80=AFPM Poul-Henning Kamp dk> wrote: > > > Regarding the specific suggestion above, I don't think we would be > satisfied with this model. In the security barriers diagram [1] we > identified the following roles: > > - ADMIN > -

Re: Idea for multi-level CLI access control

2023-06-27 Thread Dridi Boukelmoune
On Mon, Jun 26, 2023 at 6:39 PM Poul-Henning Kamp wrote: > > We talked about the overall security model during bugwash today and > while trimming the hedges I had the following idea: > > Today the fundamental authentication to open a CLI port is that > that you have access to the exact and entire

Idea for multi-level CLI access control

2023-06-26 Thread Poul-Henning Kamp
We talked about the overall security model during bugwash today and while trimming the hedges I had the following idea: Today the fundamental authentication to open a CLI port is that that you have access to the exact and entire contents of the "secret" file and can generate a proof of this. We k