On Fri, 2012-10-05 at 15:35 +0200, Martin Kosek wrote:
> On 10/05/2012 03:27 PM, Alexander Bokovoy wrote:
> > On Tue, 02 Oct 2012, Simo Sorce wrote:
> >> On Tue, 2012-10-02 at 21:29 +0200, Sumit Bose wrote:
> >>> Hi,
> >>>
> >>> this patch should fix https://fedorahosted.org/freeipa/ticket/2955 by
> >>> adding a fallback group as described in comment 2 of the ticket in
> >>> ipa-adtrust-install.
> >>>
> >>> If you prefer to use a different kind of group I can change the patch
> >>> accordingly.
> > Patch works for me, so ACK except the group name.
> > 
> >> Yes I think we should use a more natural group name. In my recent
> >> testing I have been using the name 'Trust Users' that pairs well with
> >> another group we create called 'Trust Admins'. But I am open to
> >> suggestions on a better name, 'Domain Users' may be better if we really
> >> want to associate the wellknown SID to this group.
> > I'm fine with 'Trust Users'.
> 
> We may also want to add "Trust Users" (or other name we settle on) to
> PROTECTED_GROUPS list in group.py. This should prevent user accidentally
> deleting or renaming the group.

+1

Simo.

-- 
Simo Sorce * Red Hat, Inc * New York

_______________________________________________
Freeipa-devel mailing list
Freeipa-devel@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-devel

Reply via email to