A fix for the default read ACIs. See commit message. -- Petr³
From a91f37a62c88ef83e0d745493218d0446331e3e3 Mon Sep 17 00:00:00 2001 From: Petr Viktorin <[email protected]> Date: Mon, 23 Jun 2014 13:37:33 +0200 Subject: [PATCH] netgroup: Add objectclass attribute to read permissions
The entries were unreadable without this. Additional fix for: https://fedorahosted.org/freeipa/ticket/3566 --- ACI.txt | 4 ++-- ipalib/plugins/netgroup.py | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/ACI.txt b/ACI.txt index 18e4e27372d15d756ccaba9124c0f09f3d0bfdd4..acc38ed325f4e4d352ba81c4813a2f4bd5fa0733 100644 --- a/ACI.txt +++ b/ACI.txt @@ -71,9 +71,9 @@ aci: (targetattr = "krbdefaultencsalttypes || krbmaxrenewableage || krbmaxticket dn: cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=example aci: (targetattr = "krbmaxrenewableage || krbmaxticketlife")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read User Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=example";) dn: cn=System: Read Netgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=example -aci: (targetattr = "externalhost || member || memberhost || memberof || memberuser")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";) +aci: (targetattr = "externalhost || member || memberhost || memberof || memberuser || objectclass")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";) dn: cn=System: Read Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=example -aci: (targetattr = "cn || description || hostcategory || ipaenabledflag || ipauniqueid || nisdomainname || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";) +aci: (targetattr = "cn || description || hostcategory || ipaenabledflag || ipauniqueid || nisdomainname || objectclass || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";) dn: cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=example aci: (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=example";) dn: cn=System: Read Permissions,cn=permissions,cn=pbac,dc=ipa,dc=example diff --git a/ipalib/plugins/netgroup.py b/ipalib/plugins/netgroup.py index 8603f4cea377bc46ea7efa4162ce02d786fb8f5b..06fbc20f9f56a275bab1385cc0c2275a86f8b908 100644 --- a/ipalib/plugins/netgroup.py +++ b/ipalib/plugins/netgroup.py @@ -115,7 +115,7 @@ class netgroup(LDAPObject): 'ipapermright': {'read', 'search', 'compare'}, 'ipapermdefaultattr': { 'cn', 'description', 'hostcategory', 'ipaenabledflag', - 'ipauniqueid', 'nisdomainname', 'usercategory' + 'ipauniqueid', 'nisdomainname', 'usercategory', 'objectclass', }, }, 'System: Read Netgroup Membership': { @@ -124,7 +124,7 @@ class netgroup(LDAPObject): 'ipapermright': {'read', 'search', 'compare'}, 'ipapermdefaultattr': { 'externalhost', 'member', 'memberof', 'memberuser', - 'memberhost', + 'memberhost', 'objectclass', }, }, } -- 1.9.3
_______________________________________________ Freeipa-devel mailing list [email protected] https://www.redhat.com/mailman/listinfo/freeipa-devel
