ntop / ntopng

Web-based Traffic and Security Network Traffic Monitoring
http://www.ntop.org
GNU General Public License v3.0
6.11k stars 646 forks source link

Improve LDAPS access #6772

Open MatteoBiscosi opened 2 years ago

MatteoBiscosi commented 2 years ago

What would you like to add or change?: It is requested to grant LDAPS authenticated users (ie. non-admin users) access to Historical Flows for the entire security group.

Other then that add the ability to use most-privileged access rather than the default least-privileged (for example, we could have a group called sg-ntopng-admins and put the administrative users in this group and provide access to everyone else using a standard all-users group).

lucaderi commented 2 years ago

In a multi-user environment, users can have restrictions in terms of the hosts they can view. If we enable historical flows we have the problem that we cannot honour this setting, so I am against this ticket. Probably what we need to do is to create another type of non-admin user with access to historical data

mzac commented 4 months ago

I agree with the request and the solution. Our security team doesn't have admin access to our NTOP instance as we (the network team) maintain it however they do want access to historical flows.