Easy user administration for weather maps

Support questions about the Network Weather Map plugin

Moderators: Developers, Moderators

Post Reply
sstavdal
Posts: 5
Joined: Tue Nov 04, 2014 2:48 am

Easy user administration for weather maps

Post by sstavdal »

Hello,

We have enabled LDAP authentication for Cacti, previously we had role-based login.
As a result we now have a number of user profiles, which I would like to give access to the weathermap plugin.

Currently, I have to open each map (quite a few of them), and add each user individually.
Needless to say, this is going to take time both for setup and ongoing administration (people coming/going etc).

Is there a smart way to manage weathermap access based on policies, roles etc ?
Or, at least if I could do a once off initial setup via scripts, where would I look for authentication data ?

Cheers,
Simon.
sstavdal
Posts: 5
Joined: Tue Nov 04, 2014 2:48 am

Re: Easy user administration for weather maps

Post by sstavdal »

Anyone ?
User avatar
Howie
Cacti Guru User
Posts: 5508
Joined: Thu Sep 16, 2004 5:53 am
Location: United Kingdom
Contact:

Re: Easy user administration for weather maps

Post by Howie »

Cacti itself doesn't really do groups, so neither does weathermap...

It would be pretty simple to have a cli tool to change weathermap permissions. The nicest would be some kind of hook to use when the ldap users are first created, I guess, but what would the definition look like?

That's a serious question - what UI would you expect to see in either Cacti or the weathermap admin? All LDAP users are treated equally aren't they? So maybe a placeholder 'and any new users' user?
Weathermap 0.98a is out! & QuickTree 1.0. Superlinks is over there now (and built-in to Cacti 1.x).
Some Other Cacti tweaks, including strip-graphs, icons and snmp/netflow stuff.
(Let me know if you have UK DevOps or Network Ops opportunities, too!)
sstavdal
Posts: 5
Joined: Tue Nov 04, 2014 2:48 am

Re: Easy user administration for weather maps

Post by sstavdal »

Hi Howie,

So, as far as I can see, there is no way to do this (yet).

Re: That's a serious question - what UI would you expect to see in either Cacti or the weathermap admin? All LDAP users are treated equally aren't they? So maybe a placeholder 'and any new users' user?

As you state, cacti doesn't do groups, but if it did, the ldap authentication could be tied to groups, not globally in Cacti.
That way, you could do a first match with more to less access.
I.e, if a user exist in two ad groups, on rw (readWrite) and one ro(read) for instance.
User groups need to be ordered in a more to less access fashion.
The rw group would be checked first, then the RO group.
First match for user authentication would place the user in that group, and give permissions accordingly.

These changes would obviously take some time to change/implement, but it could help centralise the administration of user access in one place, not separately for cacti and plugins.

/S
Post Reply

Who is online

Users browsing this forum: No registered users and 0 guests