IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Restore default ACLs

    Posted 08/29/21 02:36 PM
    Dear All,

    I would like to ask whether someone knows any solution to restore default ACLs.   Like default-root.  Normally this ACL contains iv-admin group. But for some reason we lost it. Now we cannot add it back because nobody has rights :-/

    So, I'm thinking whether it is any possible way to  restore default ACLs.  It is also a question where it is stored anyway (I mean the default ACL entries).
    I was thinking it is a local file somewhere in appliance so snapshot should contains this entries. I have tested restore from snapshot and it is working in case with local LDAP and local runtime but if runtime configured to use remote LDAP and also remote DB (runtime , configuration) the restore from snapshot  don't restore default ACLs (at least in my tests). So in policy management an example I cannot open object spaces.

    Yes I know it shouldn't happen to remove iv-admin but it has been happened. So before I decide to use an older backup I would like to check another solutions too if there is any.


    ------------------------------
    Regards,
    Janos Laszlo Horvath
    ------------------------------


  • 2.  RE: Restore default ACLs

    Posted 08/30/21 03:03 AM
    Janos,

    I personally don't know of any mechanism by which you can restore default ACLs without manually changing the ACLs (providing you have the correct permissions).  The ACL definitions are stored in the Policy Database, which is a local file on the file system.  So, you should be able to restore the default ACLs from a snapshot - regardless of whether the LDAP server is local or remote.  The ACLs do however embed the secUUID field from the security user entry in the LDAP server - so, when restoring the snapshot with an external LDAP server you also need to ensure that the external LDAP server (and more specifically, the secAuthority=Default suffix) corresponds to the snapshot.

    I hope that this helps.

    ------------------------------
    Scott Exton
    IBM
    Gold Coast
    ------------------------------



  • 3.  RE: Restore default ACLs

    Posted 09/01/21 02:29 AM
    Hello Scott,


    Thank you for the information.  It helps a lot.

    Regards,
    János

    ------------------------------
    Janos Laszlo Horvath
    ------------------------------