Question on Host Contact Permissions
Posted: Fri Aug 09, 2013 3:50 pm
Hello! I've done a search and I found some people asking the opposite of what I'm looking for, so I'll throw this out.
Our department has an instance of Nagios (3.5.0) and we're gearing up to allow limited access to others outside our department. When I assign a contact to a host, the user can see the host as expected, but when they click on host groups, they can see all the other hosts in that group. They cannot view any services, but they see that it's up (or down). The same goes with Service Groups - they can see the summary with host status summary and service status summary, but cannot drill down further. Essentially a host contact can see some trivial information about other systems (or a list of systems in the groups this host is a part of) but nothing beyond that. We would rather these users not see anything beyond what we give them.
I'd configured a 3.2 environment quite a while back with some DBAs and programmers having limited access and I don't recall this being an issue then, but that was a few years ago. Have I missed something here?
Support information - the host contact is an AD user not defined in any way in the cgi.cfg. The contact is not a part of an AD group defined in the apache configuration for the admins. The contact is not a member of the admin group in the contacts.cfg file. If the contact is defined in the service definition versus the host definition, all appears as expected and the user is shown "It appears as though ..." message. I have not yet gone back to create a new local user to test this behavior with.
Thanks!
Our department has an instance of Nagios (3.5.0) and we're gearing up to allow limited access to others outside our department. When I assign a contact to a host, the user can see the host as expected, but when they click on host groups, they can see all the other hosts in that group. They cannot view any services, but they see that it's up (or down). The same goes with Service Groups - they can see the summary with host status summary and service status summary, but cannot drill down further. Essentially a host contact can see some trivial information about other systems (or a list of systems in the groups this host is a part of) but nothing beyond that. We would rather these users not see anything beyond what we give them.
I'd configured a 3.2 environment quite a while back with some DBAs and programmers having limited access and I don't recall this being an issue then, but that was a few years ago. Have I missed something here?
Support information - the host contact is an AD user not defined in any way in the cgi.cfg. The contact is not a part of an AD group defined in the apache configuration for the admins. The contact is not a member of the admin group in the contacts.cfg file. If the contact is defined in the service definition versus the host definition, all appears as expected and the user is shown "It appears as though ..." message. I have not yet gone back to create a new local user to test this behavior with.
Thanks!