Ad Widget

Collapse

User access permissions

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • ralf
    Junior Member
    • Jun 2009
    • 8

    #1

    User access permissions

    We're using zabbix-1.8.1, and we're about to upgrade to 1.8.2. We're experiencing a most annoying access permissions problem. When a new users' group is about to be created, on the user group creation screen if you click on the 'User rights (show)' link, the 'Deny' column for user's rights is pre-populated with all the hosts/hostgroups that already exist and there is no way that column can be emptied. This causes all kinds of access rights for users belonging to the newly created group. The biggest problem we're experiencing is that if a user belongs to two or more usergroups, and the two usergroups have write access to different hostgroups, the user in question will not have access to any of the hosts defined in the hostgroups to which he is supposed to have write access. In the 'Configuration-Hosts' screen, no hosts show up. The screen is empty. Right now, the only way we have found to go forward with daily business is to make sure every user is only defined to belong to one usergroup, and that usergroup has write access only to one hostgroup. This is certainly a management nightmare.

    Please help. How can I make a user able to belong to more than one usergroup with access to more than one hostgroup and not have access permission problems?

    Thank you very much for any help provided.

    Regards;

    Al.
  • CeeEss
    Senior Member
    Zabbix Certified Specialist
    • Nov 2007
    • 103

    #2
    This sounds similar to the anomalous permissions issues i had migrating from 1.6.4 to 1.8.1. I thought i was going out my mind. I'd seriously think on taking the server to 1.8.2-stable or even 1.8.3. A lot of stuff has been fixed under the hood.

    cheers,

    Comment

    • ralf
      Junior Member
      • Jun 2009
      • 8

      #3
      Thanks for the fast reply CeeEss. I'm about to get 1.8.2 into production. I sure hope this has been taken care of on this new release.

      Best regards;

      Al.

      Comment

      • ralf
        Junior Member
        • Jun 2009
        • 8

        #4
        I have just upgraded to 1.8.2 from 1.8.1 and the issue still exists. Has anyone experienced this behavior? Does anybody have any workarounds?

        When a user belongs to more than one usergroup, and the usergroups he belongs to, have 'write' permissions to diferent hostgroups, in the 'Configuration->Hosts' screen no hosts/hostgroups show up. The screen is empty???????

        This is a great inconvenience to our user base. Which is composed of administrators that need to have write access to more than one hostgroup without becoming Zabbix super admins.

        Please help.

        Developers?????? Confirm? deny? comment?

        Regards;

        Al.

        Comment

        • CeeEss
          Senior Member
          Zabbix Certified Specialist
          • Nov 2007
          • 103

          #5
          Do permissions for the groups conflict? Perhaps Zabbix uses the perms from the lowest-privileged group? Are any of the groups/hosts specifically denied when youdislay Rights for one of the users in question?

          Comment

          • Aly
            ZABBIX developer
            • May 2007
            • 1126

            #6
            If no permissions defined for some host-groups for user those get into deny column.
            Zabbix | ex GUI developer

            Comment

            • ralf
              Junior Member
              • Jun 2009
              • 8

              #7
              I'm sooooo sorry

              Indeed, I did have conflicting permissions for some of the hostgroups. Correcting those conflicts fixed the permissions problem. Another case of a confused admin.

              Thank you CeeEss and Aly for your replies.

              Best regards;

              Al.

              Comment

              • CeeEss
                Senior Member
                Zabbix Certified Specialist
                • Nov 2007
                • 103

                #8
                Less a confused admin than a slightlyconfusing permissions system. Glad you found the source of the problem!

                Comment

                • Aly
                  ZABBIX developer
                  • May 2007
                  • 1126

                  #9
                  Originally posted by CeeEss
                  Less a confused admin than a slightlyconfusing permissions system. Glad you found the source of the problem!
                  It's very simple:
                  1. If user added to user groups with different permissions for same host group, lower permissions are selected
                  2. If none of user groups have defined permissions for host group, permissions to host group counted as deny

                  We always select the lowest possible permissions for host group/host/trigger/graph e.t.c.
                  Last edited by Aly; 10-05-2010, 08:36.
                  Zabbix | ex GUI developer

                  Comment

                  • CeeEss
                    Senior Member
                    Zabbix Certified Specialist
                    • Nov 2007
                    • 103

                    #10
                    That explains it alright!

                    thanks, Aly

                    Comment

                    • ralf
                      Junior Member
                      • Jun 2009
                      • 8

                      #11
                      In deed it does! The more you think about it, the more it makes sense.

                      Thank you all again.

                      Keep up the great work!!!

                      Comment

                      Working...