Re: [Freeipa-devel] [PATCH] 0635 Support delegating RBAC roles to service principals

2014-08-21 Thread Martin Kosek
On 08/20/2014 06:09 PM, Petr Viktorin wrote: On 08/20/2014 10:59 AM, Martin Kosek wrote: On 08/19/2014 07:49 PM, Petr Viktorin wrote: On 08/19/2014 01:41 PM, Martin Kosek wrote: On 08/19/2014 01:28 PM, Petr Viktorin wrote: Services can now be added to roles.

Re: [Freeipa-devel] [PATCH] 0635 Support delegating RBAC roles to service principals

2014-08-20 Thread Martin Kosek
On 08/19/2014 07:49 PM, Petr Viktorin wrote: On 08/19/2014 01:41 PM, Martin Kosek wrote: On 08/19/2014 01:28 PM, Petr Viktorin wrote: Services can now be added to roles. https://fedorahosted.org/freeipa/ticket/3164 I added a new integration test for checking that a service can actually use

Re: [Freeipa-devel] [PATCH] 0635 Support delegating RBAC roles to service principals

2014-08-20 Thread Martin Kosek
On 08/20/2014 10:59 AM, Martin Kosek wrote: On 08/19/2014 07:49 PM, Petr Viktorin wrote: ... Could we just add the realm if it does not exists in the service-add-member precallback? s/service-add-member/role-add-member/ Martin ___ Freeipa-devel

Re: [Freeipa-devel] [PATCH] 0635 Support delegating RBAC roles to service principals

2014-08-20 Thread Petr Viktorin
On 08/20/2014 10:59 AM, Martin Kosek wrote: On 08/19/2014 07:49 PM, Petr Viktorin wrote: On 08/19/2014 01:41 PM, Martin Kosek wrote: On 08/19/2014 01:28 PM, Petr Viktorin wrote: Services can now be added to roles. https://fedorahosted.org/freeipa/ticket/3164 I added a new integration test

Re: [Freeipa-devel] [PATCH] 0635 Support delegating RBAC roles to service principals

2014-08-19 Thread Martin Kosek
On 08/19/2014 01:28 PM, Petr Viktorin wrote: Services can now be added to roles. https://fedorahosted.org/freeipa/ticket/3164 I added a new integration test for checking that a service can actually use the right granted by a role. I don't think there's a good way to do this kind of

Re: [Freeipa-devel] [PATCH] 0635 Support delegating RBAC roles to service principals

2014-08-19 Thread Petr Viktorin
On 08/19/2014 01:41 PM, Martin Kosek wrote: On 08/19/2014 01:28 PM, Petr Viktorin wrote: Services can now be added to roles. https://fedorahosted.org/freeipa/ticket/3164 I added a new integration test for checking that a service can actually use the right granted by a role. I don't think