Given a user other then 'admin' full admin rights

  • Only the admin user has full control in the WebGUI. I don't think it is possible to have another user with that full functionality. If it is possible, then it is undocumented. What is your use case for needing this?

    --
    Google is your friend and Bob's your uncle!


    OMV AMD64 7.x on headless Chenbro NR12000 1U 1x 8m Quad Core E3-1220 3.1GHz 32GB ECC RAM.

  • votdev

    Hat das Label gelöst hinzugefügt.
    • Offizieller Beitrag

    admin is hard coded. Volker has asked for PRs if this is needed.

    omv 7.0.5-1 sandworm | 64 bit | 6.8 proxmox kernel

    plugins :: omvextrasorg 7.0 | kvm 7.0.13 | compose 7.1.4 | k8s 7.1.0-3 | cputemp 7.0.1 | mergerfs 7.0.4


    omv-extras.org plugins source code and issue tracker - github - changelogs


    Please try ctrl-shift-R and read this before posting a question.

    Please put your OMV system details in your signature.
    Please don't PM for support... Too many PMs!

  • Only the admin user has full control in the WebGUI. I don't think it is possible to have another user with that full functionality. If it is possible, then it is undocumented. What is your use case for needing this?


    I use pfsense for years and just trying to compare and see many high level similarities.


    Although I don't have a use case, and think users can "live" with hard-coded "admin", it'd be much better to be able to allow another user as well, say for security purposes have full access, so "admin" alias is not used at all


    Makes sense ?

  • Makes sense to me if all user actions were logged by username. Then you could tell who did what or who broke what :(

    --
    Google is your friend and Bob's your uncle!


    OMV AMD64 7.x on headless Chenbro NR12000 1U 1x 8m Quad Core E3-1220 3.1GHz 32GB ECC RAM.

    • Offizieller Beitrag

    Why let him know that OMV default user is "admin"??

    They know you have a "root" account too.

    omv 7.0.5-1 sandworm | 64 bit | 6.8 proxmox kernel

    plugins :: omvextrasorg 7.0 | kvm 7.0.13 | compose 7.1.4 | k8s 7.1.0-3 | cputemp 7.0.1 | mergerfs 7.0.4


    omv-extras.org plugins source code and issue tracker - github - changelogs


    Please try ctrl-shift-R and read this before posting a question.

    Please put your OMV system details in your signature.
    Please don't PM for support... Too many PMs!

    • Offizieller Beitrag

    Same argument, why ? Allow OMV owner decide and disable root and admin users and use a new user(s) as admin !


    Illogical ?

    You can disable root ssh access from the omv web interface. The admin user really doesn't bother me because I don't expose the the web interface to the internet. If an attacker was inside you network, you have big problems. Use a very strong password for the admin user. Problem solved. Lots of things (microsoft sql server with sa for example) use a hard coded super user name.

    omv 7.0.5-1 sandworm | 64 bit | 6.8 proxmox kernel

    plugins :: omvextrasorg 7.0 | kvm 7.0.13 | compose 7.1.4 | k8s 7.1.0-3 | cputemp 7.0.1 | mergerfs 7.0.4


    omv-extras.org plugins source code and issue tracker - github - changelogs


    Please try ctrl-shift-R and read this before posting a question.

    Please put your OMV system details in your signature.
    Please don't PM for support... Too many PMs!

  • You can disable root ssh access from the omv web interface. The admin user really doesn't bother me because I don't expose the the web interface to the internet. If an attacker was inside you network, you have big problems. Use a very strong password for the admin user. Problem solved. Lots of things (microsoft sql server with sa for example) use a hard coded super user name.


    and they get hacked !!! :P

    • Offizieller Beitrag

    While knowing the username helps, the password is most important. If you have a 24 character password, how long is going to take to brute force that even if you know the username??

    omv 7.0.5-1 sandworm | 64 bit | 6.8 proxmox kernel

    plugins :: omvextrasorg 7.0 | kvm 7.0.13 | compose 7.1.4 | k8s 7.1.0-3 | cputemp 7.0.1 | mergerfs 7.0.4


    omv-extras.org plugins source code and issue tracker - github - changelogs


    Please try ctrl-shift-R and read this before posting a question.

    Please put your OMV system details in your signature.
    Please don't PM for support... Too many PMs!

  • But assuming it's a trivial change in design - why not ?

    What makes you think this change in design would be trivial?


    You are aware that OMV is open source, right? Feel free to make whatever changes you want.

    --
    Google is your friend and Bob's your uncle!


    OMV AMD64 7.x on headless Chenbro NR12000 1U 1x 8m Quad Core E3-1220 3.1GHz 32GB ECC RAM.

    • Offizieller Beitrag

    One reason might be that some of the users are confused already about user name to use for GUI login vs. ssh login.

    Another layer of complexity for giving support.


    BTW: did you notice that it is very common to use predictable user names for all sorts of applications even in professional environment. Think of e-mail address or user names that are composed by x-letters of first name + y-letters of last name. Strong password is really the key.

Jetzt mitmachen!

Sie haben noch kein Benutzerkonto auf unserer Seite? Registrieren Sie sich kostenlos und nehmen Sie an unserer Community teil!