Forum Discussion
GaryZ_31658
Mar 28, 2006Historic F5 Account
Permissions - Sample Scripts working a little tooo well
I downloaded iControl 4.6.3 for Unix to explore doing some basic stuff (node enable/disable) and extracting stats from a BIG-IP 4.5.12.
Working with the script ../sdk/support/SOAP/perl/LocalLB/LocalLBNode.pl, I was happy to see it working great and as expected.
I was not so happy to see that the user account I was working with had Web Read Only Permissions on the BIG-IP.
Is this normal? Is there something I am missing? We allow users to log on to BIG-IP to review stats and such. I would not like for them to be able to "enable/disable" nodes.
I am suddenly concerned that any user with a route to my BIG-IP and a "Web Read Only" Account can control much more than just accessing the configuration and looking at statistics using this download.
- That's not supposed to be the case. In 4.x, if the user has the the "corba_iControl" or "soap_iControl" privilege then that user is allowed to make method calls. From what I can remember that was only Administrative accounts, not read-only users.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects