#ident "@(#)issues 1.3 07/08/07 SAC" LSARC/2007/392 Visual Panels Submitter: tasha.westmore@sun.com Owner: alan.coopersmith@sun.com Inception review 08/07/2007 gw-1 20Q 15.10 enabling Cacao * Is this done in a "local" mode to meet SBD and the SMF Policy? http://opensolaris.org/os/community/arc/policies/SMF-policy/ I don't seem to find the service manifest for Cacao gw-2 Spec p 3 Accessing VP * Does "login as a different user" mean login as a Role? * Is the list of Roles the user can assume ala SMC, Trusted Solaris or Trusted Extensions? * In the login context, where and how is the authentication audited? gw-3 Spec p 3 Remote access * username and password seems unfriendly, could/should Kerberos be applied here? gw-4 Spec p 12 PAM authentication * This doesn't seem to meet the SAC PAM policy which predates Cacao. http://opensolaris.org/os/community/arc/policies/PAM/ LSARC, how will this be remedied? Embedded_su seems to have solved this all in a CLI fashion. * Is the authenticated user's process running in the full user context? * How is the SAC Solaris Audit policy (around authentication met)? http://opensolaris.org/os/community/arc/policies/audit-policy/ gw-5 Spec p 13 Authorization * How does this fit with svc.configd doing the authorization enforcement for the authenticated user? Is what I read here just a filter so the user doesn't see things that configd won't permit? How are the two kept in sync? * How is the SAC Solaris Audit policy met? http://opensolaris.org/os/community/arc/policies/audit-policy/ gw-6 Spec in general * How does Visual Panels meet the Solaris Audit policy in general? http://opensolaris.org/os/community/arc/policies/audit-policy/ svc.configd enforce authorization and audit requests when made in the user (roles) context. pfexec will do the same for CLIs. gw-7 Spec p 14-16 * How are these Panels RBAC driven? * gw-6 Whiteboard issues. gw-8 How is this project aligned with Lockhart? They both seem to be containers. What projects should use Lockhart vs Visual Panels?