You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenDDS Security权限允许规则不生效,拒绝规则正常问题咨询

问题

在Windows环境下使用OpenDDS 3.29.1搭配ACE 8.0.1,已启用Security功能,试图通过用户证书配置治理与权限文件,实现每个参与者仅能访问特定主题列表。

当前权限配置文件如下,但无论在<allow_rule>中配置哪些主题(甚至用通配符覆盖全部),OpenDDS都会执行默认的DENY操作。有趣的是,如果通过<deny_rule>定义拒绝的主题,并将默认操作设为ALLOW,功能符合预期,日志会显示匹配到<deny_rule>列表。

请问这是OpenDDS库的bug,还是权限配置有误?

权限配置文件:

<?xml version="1.0" encoding="utf-8"?>
<dds xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="OpenDDS/omg_shared_ca_permissions.xsd">
    <permissions>
        <grant name="MPPermission">
            <subject_name>C=Op,ST=OpenDDS,L=OpenDDS,O=OpenDDS,OU=OpenDDS,CN=mp</subject_name>
            <validity>
                <!-- Format is CCYY-MM-DDThh:mm:ss[Z|(+|-)hh:mm] in GMT -->
                <not_before>2015-09-15T01:00:00</not_before>
                <not_after>2025-09-15T01:00:00</not_after>
            </validity>
            <allow_rule>
                <domains>
                    <id_range>
                        <min>1</min>
                        <max>100</max>
                    </id_range>
                </domains>
                <publish>
                    <topics>
                        <topic>TopicA</topic>
                    </topics>
                </publish>
                <subscribe>
                    <topics>
                        <topic>TopicB</topic>
                    </topics>
                </subscribe>
            </allow_rule>
            <deny_rule>
                <domains>
                    <id_range>
                        <min>1</min>
                        <max>100</max>
                    </id_range>
                </domains>
                <publish>
                    <topics>
                        <topic>TopicC</topic>
                    </topics>
                </publish>
                <subscribe>
                    <topics>
                        <topic>TopicD</topic>
                    </topics>
                </subscribe>
            </deny_rule>
            <default>DENY</default>
        </grant>
    </permissions>
</dds>
分析与解决方案

大概率是权限配置问题,而非OpenDDS的bug,可从以下几个方向排查:

  1. Subject Name 完全匹配
    配置中的<subject_name>必须与参与者证书的**完整DN(区分大小写、字段顺序、内容)**完全一致。比如你配置中C=Op,如果证书里实际是C=OP,或者字段顺序不同,这个grant会被直接忽略,所有操作触发默认DENY。而默认设为ALLOW时deny_rule生效,是因为此时即使grant未匹配,默认规则是允许,deny_rule只要匹配就会触发拒绝。

  2. 规则匹配逻辑验证
    OpenDDS权限检查顺序为:

  • 优先匹配所有deny_rule,匹配则直接拒绝
  • 再匹配所有allow_rule,匹配则允许
  • 都不匹配时执行default操作
    你当前default为DENY,若allow_rule未被匹配到,自然执行拒绝。需要确认参与者的Domain ID是否在1-100范围内,以及主题名称是否与代码中创建的完全一致(区分大小写)。
  1. 简化配置测试
    暂时删除deny_rule,只保留allow_rule和default=DENY,测试是否能正常访问TopicA/TopicB。如果仍不行,尝试用通配符<topic>*</topic>测试,若还是拒绝,说明grant本身未被匹配(大概率是subject_name问题)。

  2. 调试日志排查
    开启OpenDDS的Security调试日志(设置环境变量DCPS_DEBUG_LEVEL=10),查看日志中是否有grant匹配、规则匹配的相关输出,确认allow_rule是否被系统识别。

修正后的参考配置(假设证书DN为C=OP,ST=OpenDDS,L=OpenDDS,O=OpenDDS,OU=OpenDDS,CN=mp):

<?xml version="1.0" encoding="utf-8"?>
<dds xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="OpenDDS/omg_shared_ca_permissions.xsd">
    <permissions>
        <grant name="MPPermission">
            <subject_name>C=OP,ST=OpenDDS,L=OpenDDS,O=OpenDDS,OU=OpenDDS,CN=mp</subject_name>
            <validity>
                <not_before>2015-09-15T01:00:00</not_before>
                <not_after>2025-09-15T01:00:00</not_after>
            </validity>
            <allow_rule>
                <domains>
                    <id_range>
                        <min>1</min>
                        <max>100</max>
                    </id_range>
                </domains>
                <publish>
                    <topics>
                        <topic>TopicA</topic>
                    </topics>
                </publish>
                <subscribe>
                    <topics>
                        <topic>TopicB</topic>
                    </topics>
                </subscribe>
            </allow_rule>
            <deny_rule>
                <domains>
                    <id_range>
                        <min>1</min>
                        <max>100</max>
                    </id_range>
                </domains>
                <publish>
                    <topics>
                        <topic>TopicC</topic>
                    </topics>
                </publish>
                <subscribe>
                    <topics>
                        <topic>TopicD</topic>
                    </topics>
                </subscribe>
            </deny_rule>
            <default>DENY</default>
        </grant>
    </permissions>
</dds>

内容的提问来源于stack exchange,提问作者EP1

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.19 12:19:51