[openstack-dev] [nova][cinder][neutron][security] Rootwrap on root-intensive nodes
Nicolas Trangez
nicolas.trangez at scality.com
Thu Feb 5 13:34:25 UTC 2015
On Thu, 2015-02-05 at 08:27 -0500, Tristan Cacqueray wrote:
> Thus if we want to emulate OpenSSH design, the rpc call would also
> need to
> carry authentication data in order to prevent unwanted activity. And
> the
> rpc daemon would then need to enforce some kind of acl/policy.
Sounds a lot like what the DBus system bus implements/provides to me...
And it took quite some time to get that done.
(Note: I'm not proposing its usage in any way)
Nicolas
More information about the OpenStack-dev
mailing list