After logging into the User Portal, the user is automatically added as a admin to the RHEVM Users list without notification or intervention.

Solution Unverified - Updated -

Issue

I created a user within IPA/AD that is not added to the Users list in RHEVM -> Users tab. When those users attempt to log into the Admin Portal, they are denied access as expected.

After logging into the User Portal, the user was automatically added to the RHEVM Users list without notification or intervention. As this particular user is a member of an IPA group granted a SuperUser role in RHEVM, then the user is able to log in as an admin on the Admin Portal and get full admin privilege.

Is this expected? If yes, what precautions I need to take before giving an AD/IPA group admin role in RHEV-M?

Environment

Red Hat Enterprise Virtualization 3.0

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.