You are viewing a plain text version of this content. The canonical link for it is here.
Posted to user@guacamole.apache.org by Nick Couchman <vn...@apache.org> on 2023/03/19 18:49:52 UTC

Re: Delegated administration setup

On Fri, Jan 20, 2023 at 4:51 AM Antoine G. <gu...@placi.de> wrote:
>
> Hello,
>
> Le 18/01/2023 à 22:32, Spierings, Alphons -
> a.f.e.b.spierings@tue.nl.INVALID a écrit :
> > Acting as “administrator” we have so far not been able to setup any user
> > or user-group with the privileges to READ/UPDATE users or connections
> > apart from the ones they had created themselves.
>
> I'm also interested in the answer since I encountered roughly the same
> problem in my organization.
> We eventually decided to set up a management middleware (that has admin
> rights) to manage the users & connections.
> (because back then, I didn't have the time/knowledge to patch the whole
> Gucamole RBAC system to meet my needs).
>
> I had to play a bit with user groups to make my own RBAC without
> changing the Guacamole database schema patching the exising
> guacamole-client code.
> This solution has the drawback of not being integrated within the
> Guacamole management UI but it matched the need we have of giving people
> the autonomy they deserved.
>
> I might have been blind, and there might be a possibility to do this out
> of the box. But if so, I'm happy to see I was not the only blind one!
>

You're correct - the backend database supports most of this
functionality in terms of delegating administration, but the
management GUI bits to take advantage of it have not been implemented.

-NIck

---------------------------------------------------------------------
To unsubscribe, e-mail: user-unsubscribe@guacamole.apache.org
For additional commands, e-mail: user-help@guacamole.apache.org