You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A newly created user without any NACM group therefore has near-full read/write/exec access. The only exceptions are nodes carrying nacm:default-deny-write / nacm:default-deny-all in their YANG models.
Note
write-default: permit deviates from the RFC 8341 default (deny).
Problems
Every new feature/model is writable by all users until someone explicitly locks it down; users must continuously adapt their NACM rules.
NACM extensions cannot be added to third-party (IETF) models via deviations, so annotation alone can never cover the full tree.
exec-default: permit exposes all non-annotated RPCs/actions to any user.
Conflicts with CRA Annex I "secure by default configuration".
Current Behavior
NACM: move from opt-out to opt-in (secure-by-default)
Current state
factory-config ships with:
A newly created user without any NACM group therefore has near-full read/write/exec access. The only exceptions are nodes carrying
nacm:default-deny-write/nacm:default-deny-allin their YANG models.Note
write-default: permitdeviates from the RFC 8341 default (deny).Problems
exec-default: permitexposes all non-annotated RPCs/actions to any user.Proposal
write-default: deny,exec-default: deny(read-default: permitretained).admin(permit-all),operator(scoped write + selected RPCs),guest(read-only). Factory admin user inadmin.nacm:default-deny-all(privileged containers, mounts, host networking = host root; env may contain secrets)default-deny-all.admin); new defaults for fresh factory-config.Expected Behavior
Lets discuss!
Steps To Reproduce
No response
Additional information
No response