[tac_plus] IOS XR

Kiss Gabor (Bitman) kissg at ssg.ki.iif.hu
Fri Oct 15 10:53:20 UTC 2010


> Meanwhile I found that the following config file snippet works well:
> 
>         service = exec {
>                 task = "#operator,rwxd:bgp,rd:ospf"
>         }
> 
> The only problem I found that tac_plus - unlike IOS XR - does not
> concatenate privileges defined in various nested groups.
> It sends back the first hit only.
> So the authorization model differs depending on where authorization
> actually happens.
> 
> So I plan to modify the source in order to parse "task" keyword
> and at least concatenate all values found during inheritance.

I gave up. :-(
This would require fundamental changes in config.c.

Gabor
-- 
No smoke, no drugs, no vindoze.


More information about the tac_plus mailing list