- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: security Containment RBAC
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-16-2010 02:10 AM
тАО02-16-2010 02:10 AM
Hello,
I am not able to guess what this error means in the rbacdbchk. It only appears with an rbacdbchk, but not with one of the options alone (-r, -a, -u, -c, -R, -x), and it is not showed when -vvv is used (I can see all the checking around the DBs is done but the error is not there)
# rbacdbchk
[Invalid Authorization in role_auth DB. Auth with operation='hpux.*' and object='*' does not exist in the auths DB]
Administrator:(hpux.*, *)
In other environment this is working, being the user_role, roles, role_auth, cmd_priv and auths files the same.
Any help or clue will be welcomed, thank you in advance
#rbacdbchk -vvv
### Checking database /etc/rbac/roles
Checking field values in line: 'Administrator: Sample role shipped with system; assigned all auths by default'
...(and some more)
### Checking database /etc/rbac/auths
Checking field values in line: '(hpux.*,*):'
Checking field values in line: '(hpux.admin.boot.config,*):'
Checking field values in line: '(hpux.admin.boot.make,*):'
Checking field values in line: '(hpux.admin.boot.remove,*):'
Checking field values in line: '(hpux.admin.kernel.config,*):'
Checking field values in line: '(hpux.admin.kernel.crash.save,*):'
...
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-16-2010 02:41 AM
тАО02-16-2010 02:41 AM
Re: security Containment RBAC
I'm not very familiar with rbac, but normally as I understand the messages says that in the file /etc/rbac/role_auth you have a value
Administrator: (hpux.*, *) that is not matching the auths file. But the auths file are always like (hpux.*,*):
So maybe there is a typo error on the /etc/rbac/role_auth that you can not see while the rbacdbck can check it.
Copy this line from another good server could help you?
HTH
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-16-2010 05:17 AM
тАО02-16-2010 05:17 AM
Re: security Containment RBAC
They are having some issues with Ignite and maybe that's the problem but I am not sure
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-16-2010 06:05 AM
тАО02-16-2010 06:05 AM
Solution>We thought about that, but the copied all the files from the working server to the failing one and it the same error is appearing...
That's mean, the db is ok. So I suppose the problem is on the rbacdbchk command.
You write about ignite issue. What's the problem? Do you have restore this box?
Do you have check about library of rbackdbchk
ldd /usr/sbin/rbacdbchk
and compare ll
You could also check about patches like
PHCO_40362
HTH
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-17-2010 03:24 AM
тАО02-17-2010 03:24 AM