Title: #617: Allow renaming of sudo rules
Thank you Alexander for your insight. Since this was a hack, I did not want to
do it server-wise. I chose a different approach to the problem and reworked the
original idea so the rename option is now worked with on server.
With this approach, we are able to white-list objects which we think may be
allowed renaming even though their primary keys are not in their RDN.
Just for the record, the names of sudo rules are still not checked for CN
compatibility since their primary key is not part of their DN, but that's how
things have been since for ever, I am afraid (you can try `ipa sudorule-add
See the full comment at
Manage your subscription for the Freeipa-devel mailing list:
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code