[tac_plus] IOS XR
Kiss Gabor (Bitman)
kissg at ssg.ki.iif.hu
Fri Oct 15 10:53:20 UTC 2010
> Meanwhile I found that the following config file snippet works well:
>
> service = exec {
> task = "#operator,rwxd:bgp,rd:ospf"
> }
>
> The only problem I found that tac_plus - unlike IOS XR - does not
> concatenate privileges defined in various nested groups.
> It sends back the first hit only.
> So the authorization model differs depending on where authorization
> actually happens.
>
> So I plan to modify the source in order to parse "task" keyword
> and at least concatenate all values found during inheritance.
I gave up. :-(
This would require fundamental changes in config.c.
Gabor
--
No smoke, no drugs, no vindoze.
More information about the tac_plus
mailing list