Files
2026-04-24 14:29:58 +02:00
..
2026-01-23 06:12:26 +01:00
2026-04-24 14:29:58 +02:00
2026-01-23 06:12:26 +01:00
2026-01-23 06:12:26 +01:00
2026-01-23 06:12:26 +01:00

=== Basic NACM Permissions

ifdef::topdoc[:imagesdir: {topdoc}../../test/case/system/nacm-basic]

==== Description

Test that NACM groups (admin, operator, guest) correctly enforce
access control with permissive defaults and targeted denials.

The NACM design is "permit by default, deny sensitive items":

- admin: Full unrestricted access (permit-all rule)
- operator: Can configure everything EXCEPT passwords, keystore, truststore
- guest: Read-only access (explicit deny of create/update/delete/exec)

Verifies that:

- Operators can read and modify most configuration (hostname, interfaces)
- Operators CANNOT read or write password hashes (protected path)
- Guests can read but cannot modify any configuration
- Admin can access everything including passwords

==== Topology

image::topology.svg[Basic NACM Permissions topology, align=center, scaledwidth=75%]

==== Sequence

. Set up topology and attach to target
. Configure NACM groups, rules, and test users
. Verify operator can read configuration
. Verify operator can modify interface configuration
. Verify operator can modify hostname
. Verify operator cannot read password hashes
. Verify operator cannot write password hashes
. Verify guest can read configuration
. Verify guest cannot modify configuration
. Verify admin can access passwords