发明名称 Security context passing for stateless system management
摘要 Systems and methods for stateless system management are described. Examples include a method wherein a user sends the management system a request to act upon a managed system. The management system determines whether the user is authorized for the requested action. Upon authorization, the management system looks up an automation principal, which is a security principal native to the managed system. The management system retrieves connecting credentials for the automation principal, and connects to the managed system using the retrieved credentials. Once the managed system is connected, the management system performs the requested action on the managed system, and sends the result back to the user.
申请公布号 US9489499(B2) 申请公布日期 2016.11.08
申请号 US201414265923 申请日期 2014.04.30
申请人 BLADELOGIC, INC. 发明人 Knjazihhin Denis;Reilly Paul A.;Birger Chet;Solin David A.;Adams Carl
分类号 H04L9/32;G06F21/31;G06F21/60;H04L29/06 主分类号 H04L9/32
代理机构 Brake Hughes Bellermann LLP 代理人 Brake Hughes Bellermann LLP
主权项 1. A method comprising; implementing, by executing instructions on a central processing unit (CPU) coupled to a memory, a centralized configuration management system for managing a plurality of diverse computer systems, each having different respective native security principals; displaying an object graph to a user, each node of the object graph corresponding to a respective one of the diverse computer systems; receiving a request at the centralized configuration management system, from the user, for action on a particular managed computer system, the requested action being the user's ability to browse a node in the object graph corresponding to the particular managed computer system; authorizing the user's access to the node in the object graph based on the user's security context; obtaining an automation principal for the particular managed computer system corresponding to the node, the automation principal being associated with the user and the particular managed computer system, wherein the automation principal is a native security principal of the particular managed computer system; obtaining an authorization credential for the automation principal based on the user's security context; connecting to the node using the obtained authorization credential; browsing the node; and displaying a result to the user.
地址 Houston TX US