OpenDDS Security权限允许规则不生效,拒绝规则正常问题咨询
在Windows环境下使用OpenDDS 3.29.1搭配ACE 8.0.1,已启用Security功能,试图通过用户证书配置治理与权限文件,实现每个参与者仅能访问特定主题列表。
当前权限配置文件如下,但无论在<allow_rule>中配置哪些主题(甚至用通配符覆盖全部),OpenDDS都会执行默认的DENY操作。有趣的是,如果通过<deny_rule>定义拒绝的主题,并将默认操作设为ALLOW,功能符合预期,日志会显示匹配到<deny_rule>列表。
请问这是OpenDDS库的bug,还是权限配置有误?
权限配置文件:
<?xml version="1.0" encoding="utf-8"?> <dds xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="OpenDDS/omg_shared_ca_permissions.xsd"> <permissions> <grant name="MPPermission"> <subject_name>C=Op,ST=OpenDDS,L=OpenDDS,O=OpenDDS,OU=OpenDDS,CN=mp</subject_name> <validity> <!-- Format is CCYY-MM-DDThh:mm:ss[Z|(+|-)hh:mm] in GMT --> <not_before>2015-09-15T01:00:00</not_before> <not_after>2025-09-15T01:00:00</not_after> </validity> <allow_rule> <domains> <id_range> <min>1</min> <max>100</max> </id_range> </domains> <publish> <topics> <topic>TopicA</topic> </topics> </publish> <subscribe> <topics> <topic>TopicB</topic> </topics> </subscribe> </allow_rule> <deny_rule> <domains> <id_range> <min>1</min> <max>100</max> </id_range> </domains> <publish> <topics> <topic>TopicC</topic> </topics> </publish> <subscribe> <topics> <topic>TopicD</topic> </topics> </subscribe> </deny_rule> <default>DENY</default> </grant> </permissions> </dds>
大概率是权限配置问题,而非OpenDDS的bug,可从以下几个方向排查:
Subject Name 完全匹配
配置中的<subject_name>必须与参与者证书的**完整DN(区分大小写、字段顺序、内容)**完全一致。比如你配置中C=Op,如果证书里实际是C=OP,或者字段顺序不同,这个grant会被直接忽略,所有操作触发默认DENY。而默认设为ALLOW时deny_rule生效,是因为此时即使grant未匹配,默认规则是允许,deny_rule只要匹配就会触发拒绝。规则匹配逻辑验证
OpenDDS权限检查顺序为:
- 优先匹配所有
deny_rule,匹配则直接拒绝 - 再匹配所有
allow_rule,匹配则允许 - 都不匹配时执行
default操作
你当前default为DENY,若allow_rule未被匹配到,自然执行拒绝。需要确认参与者的Domain ID是否在1-100范围内,以及主题名称是否与代码中创建的完全一致(区分大小写)。
简化配置测试
暂时删除deny_rule,只保留allow_rule和default=DENY,测试是否能正常访问TopicA/TopicB。如果仍不行,尝试用通配符<topic>*</topic>测试,若还是拒绝,说明grant本身未被匹配(大概率是subject_name问题)。调试日志排查
开启OpenDDS的Security调试日志(设置环境变量DCPS_DEBUG_LEVEL=10),查看日志中是否有grant匹配、规则匹配的相关输出,确认allow_rule是否被系统识别。
修正后的参考配置(假设证书DN为C=OP,ST=OpenDDS,L=OpenDDS,O=OpenDDS,OU=OpenDDS,CN=mp):
<?xml version="1.0" encoding="utf-8"?> <dds xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="OpenDDS/omg_shared_ca_permissions.xsd"> <permissions> <grant name="MPPermission"> <subject_name>C=OP,ST=OpenDDS,L=OpenDDS,O=OpenDDS,OU=OpenDDS,CN=mp</subject_name> <validity> <not_before>2015-09-15T01:00:00</not_before> <not_after>2025-09-15T01:00:00</not_after> </validity> <allow_rule> <domains> <id_range> <min>1</min> <max>100</max> </id_range> </domains> <publish> <topics> <topic>TopicA</topic> </topics> </publish> <subscribe> <topics> <topic>TopicB</topic> </topics> </subscribe> </allow_rule> <deny_rule> <domains> <id_range> <min>1</min> <max>100</max> </id_range> </domains> <publish> <topics> <topic>TopicC</topic> </topics> </publish> <subscribe> <topics> <topic>TopicD</topic> </topics> </subscribe> </deny_rule> <default>DENY</default> </grant> </permissions> </dds>
内容的提问来源于stack exchange,提问作者EP1

