Bug 446938 - Security
Summary: Security
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise MRG
Classification: Red Hat
Component: qpid-cpp
Version: 1.0
Hardware: All
OS: Linux
urgent
high
Target Milestone: 1.1
: ---
Assignee: Carl Trieloff
QA Contact: Kim van der Riet
URL:
Whiteboard:
Depends On:
Blocks: 471304
TreeView+ depends on / blocked
 
Reported: 2008-05-16 18:00 UTC by Carl Trieloff
Modified: 2009-02-04 15:34 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-02-04 15:34:57 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHEA-2009:0035 0 normal SHIPPED_LIVE Red Hat Enterprise MRG Messaging 1.1 Release 2009-02-04 15:33:44 UTC

Description Carl Trieloff 2008-05-16 18:00:53 UTC
Description of problem:

Security features must exist so that multiple message flows can use the same
broker. There should be multiple users/groups, and the access to and use of
queues should be controlled by an access control list (ACL). The current beta
has few security features. It lack SSL, multiple users and ACL.


(Notes: Carl)

This applies to brokers and clients.

Initial file support for RBAC and ACL will be enough, however at we should also
support IPA to store ACL etc t some point.

Comment 1 Frantisek Reznicek 2008-10-31 16:15:48 UTC
No test info. Putting NEEDINFO flag.

Comment 2 Carl Trieloff 2008-11-04 19:24:35 UTC
This issue is covered by other BZ's.

To test and close the ACL side, create two users, setup one with allow all all and the other with no permissions. try useing the command line tools for both these user, one should work, the other deny.

I have just done this test and cleared this aspect of this bug.

Carl.

Comment 3 Rajith Attapattu 2008-11-06 20:10:29 UTC
As of rev 711957 all changes discussed for MRG 1.1 release is completed.
The ACL module now has an automated test suite that goes through number of scenarios. More test cases could be added.

SSL for both JMS and c++ client/Brokers have also been added and tested.
Gordon has checked in an automated test suite.
I will be adding a test profile for the java side.

Comment 5 Frantisek Reznicek 2008-11-18 16:02:49 UTC
RHTS test qpid_compilation_unit_tests performs all unit tests including acl, ssh and others. Test proves features are added.
->VERIFIED

Comment 7 errata-xmlrpc 2009-02-04 15:34:57 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHEA-2009-0035.html


Note You need to log in before you can comment on or make changes to this bug.