LDAP user with full Admin permissions unable to modify Features of LXC

FunnyManVA

New Member
Aug 2, 2019
3
3
3
50
I've successfully configured LDAP users and groups on Proxmox 6.3-6 and that works fine. I can login with an LDAP user and I've given one of the LDAP groups (admins) full privileges just like the built in root@PAM user. They look identical when I view their permissions in the Users tab. Everything appears to be available, except that the LDAP user can't edit the Features option of an LXC container. Everything else, yes, but not that one setting. The root@PAM user can, however, so it's just something not consistent between the two, but they both are Administrator roles so I would think there's nothing that the LDAP user can't do that root@PAM can.
 
hi,

the "Features" option of containers is restricted to root@pam only. this is because they can be security sensitive, e.g., the nesting option could allow an unprivileged user to break out of the container.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!