Comment 2 for bug 1033899

Revision history for this message
Thomas Goirand (thomas-goirand) wrote :

Hi,

Basically, before, anyone with an account on the box could execute commands with xe (eg: use XAPI), when what was intended was that only the root would.

What I did in the Debian SID package was creating a xapi group, then if someone is *not* in that group, or if the PAM group thing isn't uncommented, then he will not have access to XAPI. It seems that the patch for Ubuntu doesn't have the addition of the new group, in order to limit changes, which I think is fine (if someone wants to grant access to a non-root user, then the xapi group would need to be manually created, and the PAM config file for that group uncommented).

Do you understand now? If my explanations were not enough, please let me know. If you want to read more details, Mike did an advisory here:
http://lists.xen.org/archives/html/xen-api/2012-07/msg00059.html

But I don't think you need to read that much! :)

Cheers,

Thomas Goirand (zigo)