Forum Discussion
Stefan98_85555
Nimbostratus
Sep 09, 2009Restrict executable commands for an account
Hi all,
i have an script on a server, which must only enable/disable poolmembers of a specific pool. The user (which the script use) on the LTM should have no more rights than for this task. Is there an easy solution for this problem?
If the user has operator-rights, he can read all objects in the partition. I can restrict the ssh-account with a tool like authprogs.pl, but IMHO its not a good solution...
regards
- The_Bhattman
Nimbostratus
Have you looked at the samples section specifically iControls section - Stefan98_85555
Nimbostratus
No, i found no script that helps to solve my problem. I think it is a problem with the configuration. Maybe there is a possibility to restrict the rights of a to the required actions. - The_Bhattman
Nimbostratus
What version of LTM are you running? - Stefan98_85555
Nimbostratus
BIG-IP 9.4.5 Build 1086.1 Hotfix HF2 - The_Bhattman
Nimbostratus
Couldn't you create your objects in a separate partision and then assign a username to that partition? - Stefan98_85555
Nimbostratus
This seems to be the "best" possibility. I hope, that i will never need a user with rights on several partitions...
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects