A fix for the default read ACIs. See commit message.

--
PetrĀ³
From a91f37a62c88ef83e0d745493218d0446331e3e3 Mon Sep 17 00:00:00 2001
From: Petr Viktorin <pvikt...@redhat.com>
Date: Mon, 23 Jun 2014 13:37:33 +0200
Subject: [PATCH] netgroup: Add objectclass attribute to read permissions

The entries were unreadable without this.

Additional fix for: https://fedorahosted.org/freeipa/ticket/3566
---
 ACI.txt                    | 4 ++--
 ipalib/plugins/netgroup.py | 4 ++--
 2 files changed, 4 insertions(+), 4 deletions(-)

diff --git a/ACI.txt b/ACI.txt
index 18e4e27372d15d756ccaba9124c0f09f3d0bfdd4..acc38ed325f4e4d352ba81c4813a2f4bd5fa0733 100644
--- a/ACI.txt
+++ b/ACI.txt
@@ -71,9 +71,9 @@ aci: (targetattr = "krbdefaultencsalttypes || krbmaxrenewableage || krbmaxticket
 dn: cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=example
 aci: (targetattr = "krbmaxrenewableage || krbmaxticketlife")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read User Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=example";)
 dn: cn=System: Read Netgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=example
-aci: (targetattr = "externalhost || member || memberhost || memberof || memberuser")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";;)
+aci: (targetattr = "externalhost || member || memberhost || memberof || memberuser || objectclass")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";;)
 dn: cn=System: Read Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=example
-aci: (targetattr = "cn || description || hostcategory || ipaenabledflag || ipauniqueid || nisdomainname || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";;)
+aci: (targetattr = "cn || description || hostcategory || ipaenabledflag || ipauniqueid || nisdomainname || objectclass || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";;)
 dn: cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=example
 aci: (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=example";)
 dn: cn=System: Read Permissions,cn=permissions,cn=pbac,dc=ipa,dc=example
diff --git a/ipalib/plugins/netgroup.py b/ipalib/plugins/netgroup.py
index 8603f4cea377bc46ea7efa4162ce02d786fb8f5b..06fbc20f9f56a275bab1385cc0c2275a86f8b908 100644
--- a/ipalib/plugins/netgroup.py
+++ b/ipalib/plugins/netgroup.py
@@ -115,7 +115,7 @@ class netgroup(LDAPObject):
             'ipapermright': {'read', 'search', 'compare'},
             'ipapermdefaultattr': {
                 'cn', 'description', 'hostcategory', 'ipaenabledflag',
-                'ipauniqueid', 'nisdomainname', 'usercategory'
+                'ipauniqueid', 'nisdomainname', 'usercategory', 'objectclass',
             },
         },
         'System: Read Netgroup Membership': {
@@ -124,7 +124,7 @@ class netgroup(LDAPObject):
             'ipapermright': {'read', 'search', 'compare'},
             'ipapermdefaultattr': {
                 'externalhost', 'member', 'memberof', 'memberuser',
-                'memberhost',
+                'memberhost', 'objectclass',
             },
         },
     }
-- 
1.9.3

_______________________________________________
Freeipa-devel mailing list
Freeipa-devel@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-devel

Reply via email to