Using Unix groupnames in contact definitions or cgi authorization schemes

Marc Powell marc at ena.com
Tue Jan 26 14:43:01 CET 2010


On Jan 26, 2010, at 4:18 AM, Mark Elsen wrote:

> Nagios 3.x
> ----------------
> 
> - I was wondering wether one can use UNIX groupnames in contact
> defintions , or in cgi auth. directives
> such as 'authorized_for_all_service_commands=..." ; instead of having
> to use individual usernames ?

There's no Apache auth module that works like that, that I know of. All nagios does is look at the web server environment variable 'REMOTE_USER' to determine the username of the logged in user. If you can find (or write) an Apache auth module that sets REMOTE_USER to what you need then it will work.

The difficult part is that you want to change REMOTE_USER from the username passed during login to something else after authentication. I'm not sure that Apache permits/supports that.

> I need to make a simple distinction between a couple of divisions,
> regarding nagios access and
> server monitoring in our company. Using individual usernames would be
> cumbersome w.r.t  the simple
> allowed views I want to use in the NAGIOS (console).

You could create contacts and associated .htpasswd entries that are role accounts and provide the divisions with the single username/password that is theirs. That's worked well for our different NOCs.

--
Marc


------------------------------------------------------------------------------
The Planet: dedicated and managed hosting, cloud storage, colocation
Stay online with enterprise data centers and the best network in the business
Choose flexible plans and management services without long-term contracts
Personal 24x7 support from experience hosting pros just a phone call away.
http://p.sf.net/sfu/theplanet-com
_______________________________________________
Nagios-users mailing list
Nagios-users at lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nagios-users
::: Please include Nagios version, plugin version (-v) and OS when reporting any issue. 
::: Messages without supporting info will risk being sent to /dev/null





More information about the Users mailing list