Forum Discussion
Backup user account for pull backup ?
Hi,
I'm trying to consider backup of my Bigips, allowing a remote machine to pull ucs archives. I'm trying to setup an account with specific privileges, not to allow full system access but i cannot find anything about it. I'm finding out that only root or admin account are necessary. This means that if the remote backup server is compromised, then the Bigips could be.
Did someone experienced creating linux system accounts on the Bigips ?
thank you for any thought about it Aurel
14 Replies
- that might be tricky, why not have the big-ip push the ucs archive somewhere?
- Aurel
Cirrus
I would prefer the push method in many ways, but it's a design rule as we have a machine who's pulling all configurations to her. Then i have to provide like root access to my machine, and i don't like so much, but i'm afraid that would be the only way. - adrock_1854
Nimbostratus
What version are the BIG-IPs you wish to backup?
- Aurel
Cirrus
Hi Adrock, we're running 11.2.1 HF9. - adrock_1854
Nimbostratus
Does the remote account need the ability to generate the archive itself, or will it simply be pulling archives already created by some other method? - Aurel
Cirrus
They choose to generate themself the archive. That means their machine have full access with the root account. Until the machine is not compromised, it should be ok. That's definitely not the way i would choose, but they know about my opinion and will assume any further issue.
- dirtycache
Nimbostratus
What version are the BIG-IPs you wish to backup?
- Aurel
Cirrus
Hi Adrock, we're running 11.2.1 HF9. - dirtycache
Nimbostratus
Does the remote account need the ability to generate the archive itself, or will it simply be pulling archives already created by some other method? - Aurel
Cirrus
They choose to generate themself the archive. That means their machine have full access with the root account. Until the machine is not compromised, it should be ok. That's definitely not the way i would choose, but they know about my opinion and will assume any further issue.
- nitass
Employee
there are request for enhancements regarding custom defined user role but they have not been implemented yet. you may open a support case to see if it can be expedited.
ID273333 - AuthZ: User-definable roles
ID382849 - RFE: Custom Defined User Roles/Permissions on LTMs Similar to EM
- Aurel
Cirrus
Thanks for your reply Nitass. That would be definitely a good thing, but i have to confess that's not a high priority issue.
- nitass_89166
Noctilucent
there are request for enhancements regarding custom defined user role but they have not been implemented yet. you may open a support case to see if it can be expedited.
ID273333 - AuthZ: User-definable roles
ID382849 - RFE: Custom Defined User Roles/Permissions on LTMs Similar to EM
- Aurel
Cirrus
Thanks for your reply Nitass. That would be definitely a good thing, but i have to confess that's not a high priority issue.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com