Re: [Freeipa-devel] New ACIs for cn=etc

2014-04-23 Thread Petr Viktorin
On 04/14/2014 12:55 PM, Martin Kosek wrote: [...] dn: cn=masters,cn=ipa,cn=etc,SUFFIX - ADD aci allowing reading hosts (to have it separate from global cn=etc one so that we can once assign it only to ipamasters hostgroup for example) We don't have an ipamasters hostgroup. Should we? --

Re: [Freeipa-devel] New ACIs for cn=etc

2014-04-23 Thread Martin Kosek
On 04/23/2014 01:03 PM, Petr Viktorin wrote: On 04/14/2014 12:55 PM, Martin Kosek wrote: [...] dn: cn=masters,cn=ipa,cn=etc,SUFFIX - ADD aci allowing reading hosts (to have it separate from global cn=etc one so that we can once assign it only to ipamasters hostgroup for example) We don't

Re: [Freeipa-devel] New ACIs for cn=etc

2014-04-23 Thread Jan Cholasta
On 23.4.2014 13:13, Martin Kosek wrote: On 04/23/2014 01:03 PM, Petr Viktorin wrote: On 04/14/2014 12:55 PM, Martin Kosek wrote: [...] dn: cn=masters,cn=ipa,cn=etc,SUFFIX - ADD aci allowing reading hosts (to have it separate from global cn=etc one so that we can once assign it only to

Re: [Freeipa-devel] New ACIs for cn=etc

2014-04-23 Thread Simo Sorce
On Wed, 2014-04-23 at 13:03 +0200, Petr Viktorin wrote: On 04/14/2014 12:55 PM, Martin Kosek wrote: [...] dn: cn=masters,cn=ipa,cn=etc,SUFFIX - ADD aci allowing reading hosts (to have it separate from global cn=etc one so that we can once assign it only to ipamasters hostgroup for

Re: [Freeipa-devel] New ACIs for cn=etc

2014-04-23 Thread Petr Viktorin
On 04/23/2014 01:42 PM, Jan Cholasta wrote: On 23.4.2014 13:13, Martin Kosek wrote: On 04/23/2014 01:03 PM, Petr Viktorin wrote: On 04/14/2014 12:55 PM, Martin Kosek wrote: [...] dn: cn=masters,cn=ipa,cn=etc,SUFFIX - ADD aci allowing reading hosts (to have it separate from global cn=etc one

Re: [Freeipa-devel] New ACIs for cn=etc

2014-04-17 Thread Petr Viktorin
On 04/16/2014 03:04 PM, Simo Sorce wrote: On Wed, 2014-04-16 at 15:00 +0200, Petr Viktorin wrote: Simo, Rob, would you be OK with changing virtual operation objectclass to our own one to have a better control over it? No, in general I am not ok to change objects that already exist in IPA

Re: [Freeipa-devel] New ACIs for cn=etc

2014-04-16 Thread Petr Viktorin
On 04/14/2014 04:00 PM, Simo Sorce wrote: On Mon, 2014-04-14 at 12:55 +0200, Martin Kosek wrote: When heading for a lunch today, I had a discussion with Petr3 about ACIs for cn=etc,SUFFIX. On our initial meeting back at DevConf.cz time, we said we will simply allow all attributes in cn=etc for

Re: [Freeipa-devel] New ACIs for cn=etc

2014-04-16 Thread Simo Sorce
On Wed, 2014-04-16 at 13:31 +0200, Martin Kosek wrote: On 04/16/2014 12:50 PM, Petr Viktorin wrote: On 04/14/2014 04:00 PM, Simo Sorce wrote: On Mon, 2014-04-14 at 12:55 +0200, Martin Kosek wrote: When heading for a lunch today, I had a discussion with Petr3 about ACIs for

Re: [Freeipa-devel] New ACIs for cn=etc

2014-04-16 Thread Petr Viktorin
On 04/16/2014 02:55 PM, Simo Sorce wrote: On Wed, 2014-04-16 at 13:31 +0200, Martin Kosek wrote: On 04/16/2014 12:50 PM, Petr Viktorin wrote: On 04/14/2014 04:00 PM, Simo Sorce wrote: On Mon, 2014-04-14 at 12:55 +0200, Martin Kosek wrote: When heading for a lunch today, I had a discussion

Re: [Freeipa-devel] New ACIs for cn=etc

2014-04-16 Thread Simo Sorce
On Wed, 2014-04-16 at 15:00 +0200, Petr Viktorin wrote: Simo, Rob, would you be OK with changing virtual operation objectclass to our own one to have a better control over it? No, in general I am not ok to change objects that already exist in IPA as it make upgrades with new and old

Re: [Freeipa-devel] New ACIs for cn=etc

2014-04-14 Thread Simo Sorce
On Mon, 2014-04-14 at 12:55 +0200, Martin Kosek wrote: When heading for a lunch today, I had a discussion with Petr3 about ACIs for cn=etc,SUFFIX. On our initial meeting back at DevConf.cz time, we said we will simply allow all attributes in cn=etc for authenticated users and will just exclude