Re: [Freeipa-devel] [PATCHES] 0583-0584 Convert DNS default permissions to managed

2014-06-18 Thread Martin Kosek
On 06/16/2014 05:43 PM, Petr Viktorin wrote: On 06/13/2014 05:25 PM, Petr Viktorin wrote: With the first patch, old SYSTEM permissions can be replaced. The Read DNS Entries did not have an associated ACI, but was rather rolled into a single ACI with the managedBy rule used for per-zone

Re: [Freeipa-devel] [PATCHES] 0583-0584 Convert DNS default permissions to managed

2014-06-18 Thread Martin Kosek
On 06/18/2014 02:20 PM, Petr Viktorin wrote: On 06/18/2014 02:05 PM, Martin Kosek wrote: On 06/16/2014 05:43 PM, Petr Viktorin wrote: On 06/13/2014 05:25 PM, Petr Viktorin wrote: With the first patch, old SYSTEM permissions can be replaced. The Read DNS Entries did not have an associated

Re: [Freeipa-devel] [PATCHES] 0583-0584 Convert DNS default permissions to managed

2014-06-18 Thread Petr Viktorin
On 06/18/2014 02:23 PM, Martin Kosek wrote: On 06/18/2014 02:20 PM, Petr Viktorin wrote: On 06/18/2014 02:05 PM, Martin Kosek wrote: [...] 583.2: OK 584.2: 1) Typo in description: Convewrt the existing default permissions. Thanks for the catch, I'll fix it before pushing. 2) What would

Re: [Freeipa-devel] [PATCHES] 0583-0584 Convert DNS default permissions to managed

2014-06-18 Thread Petr Viktorin
On 06/18/2014 02:23 PM, Martin Kosek wrote: On 06/18/2014 02:20 PM, Petr Viktorin wrote: On 06/18/2014 02:05 PM, Martin Kosek wrote: [...] 583.2: OK 584.2: 1) Typo in description: Convewrt the existing default permissions. Thanks for the catch, I'll fix it before pushing. 2) What would

Re: [Freeipa-devel] [PATCHES] 0583-0584 Convert DNS default permissions to managed

2014-06-16 Thread Petr Viktorin
On 06/13/2014 05:25 PM, Petr Viktorin wrote: With the first patch, old SYSTEM permissions can be replaced. The Read DNS Entries did not have an associated ACI, but was rather rolled into a single ACI with the managedBy rule used for per-zone access. (and before that it was part of a deny rule.)

[Freeipa-devel] [PATCHES] 0583-0584 Convert DNS default permissions to managed

2014-06-13 Thread Petr Viktorin
With the first patch, old SYSTEM permissions can be replaced. The Read DNS Entries did not have an associated ACI, but was rather rolled into a single ACI with the managedBy rule used for per-zone access. (and before that it was part of a deny rule.) We can't remove this permission in an