Hi,

It seems that when using the EC2 API, the security group implementation does 
not enforce RBAC policy for the add_rules, remove_rules, destroy and other 
functions (in compute/api.py). Only the add_to_instance and 
remove_from_instance functions enforce RBAC. This seems like an oversight for 
obvious reasons.

The Nova API security group implementation does enforce RBAC on these functions.

Does anyone know why?

Thanks in advance.

-m



_______________________________________________
Mailing list: http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack
Post to     : openstack@lists.openstack.org
Unsubscribe : http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack

Reply via email to