[openstack-dev] [nova][cinder][neutron][security] Rootwrap on root-intensive nodes

Nicolas Trangez nicolas.trangez at scality.com
Thu Feb 5 13:34:25 UTC 2015


On Thu, 2015-02-05 at 08:27 -0500, Tristan Cacqueray wrote:
> Thus if we want to emulate OpenSSH design, the rpc call would also
> need to
> carry authentication data in order to prevent unwanted activity. And
> the
> rpc daemon would then need to enforce some kind of acl/policy.

Sounds a lot like what the DBus system bus implements/provides to me...
And it took quite some time to get that done.

(Note: I'm not proposing its usage in any way)

Nicolas




More information about the OpenStack-dev mailing list