Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Alexander Bokovoy
On Thu, 04 Sep 2014, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014 01:27 PM, Petr Viktorin wrote: Hello, This adds managed

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Alexander Bokovoy
On Fri, 05 Sep 2014, Alexander Bokovoy wrote: On Thu, 04 Sep 2014, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014 01:27 PM,

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Martin Kosek
On 09/05/2014 09:03 AM, Alexander Bokovoy wrote: On Fri, 05 Sep 2014, Alexander Bokovoy wrote: On Thu, 04 Sep 2014, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Martin Kosek
On 09/04/2014 04:44 PM, Ludwig Krispenz wrote: On 09/04/2014 04:38 PM, Martin Kosek wrote: On 09/04/2014 04:10 PM, Alexander Bokovoy wrote: ... createTimestamp is operational attribute and is synthesized by slapi-nis, there is no problem allowing access to it. I think we can allow

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Alexander Bokovoy
On Fri, 05 Sep 2014, Martin Kosek wrote: On 09/04/2014 04:44 PM, Ludwig Krispenz wrote: On 09/04/2014 04:38 PM, Martin Kosek wrote: On 09/04/2014 04:10 PM, Alexander Bokovoy wrote: ... createTimestamp is operational attribute and is synthesized by slapi-nis, there is no problem allowing

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Petr Viktorin
On 09/05/2014 09:18 AM, Martin Kosek wrote: On 09/05/2014 09:03 AM, Alexander Bokovoy wrote: On Fri, 05 Sep 2014, Alexander Bokovoy wrote: On Thu, 04 Sep 2014, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Alexander Bokovoy
On Fri, 05 Sep 2014, Petr Viktorin wrote: On 09/05/2014 09:18 AM, Martin Kosek wrote: On 09/05/2014 09:03 AM, Alexander Bokovoy wrote: On Fri, 05 Sep 2014, Alexander Bokovoy wrote: On Thu, 04 Sep 2014, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014,

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Petr Viktorin
On 09/05/2014 01:34 PM, Alexander Bokovoy wrote: On Fri, 05 Sep 2014, Petr Viktorin wrote: On 09/05/2014 09:18 AM, Martin Kosek wrote: ... Thanks! Looks sane to me. We would just need to remove Views related ACIs for the 4.0.x version that we will need for today. Thanks indeed! Here is the

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Simo Sorce
On Fri, 2014-09-05 at 12:12 +0300, Alexander Bokovoy wrote: On Fri, 05 Sep 2014, Martin Kosek wrote: On 09/04/2014 04:44 PM, Ludwig Krispenz wrote: On 09/04/2014 04:38 PM, Martin Kosek wrote: On 09/04/2014 04:10 PM, Alexander Bokovoy wrote: ... createTimestamp is operational attribute

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Petr Viktorin
On 09/05/2014 01:51 PM, Petr Viktorin wrote: On 09/05/2014 01:34 PM, Alexander Bokovoy wrote: On Fri, 05 Sep 2014, Petr Viktorin wrote: On 09/05/2014 09:18 AM, Martin Kosek wrote: ... Thanks! Looks sane to me. We would just need to remove Views related ACIs for the 4.0.x version that we will

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Alexander Bokovoy
On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014 01:27 PM, Petr Viktorin wrote: Hello, This adds managed read permissions to the compat tree. For users it grants anonymous access; authenticated

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Martin Kosek
On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014 01:27 PM, Petr Viktorin wrote: Hello, This adds managed read permissions to the compat tree. For

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Alexander Bokovoy
On Thu, 04 Sep 2014, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014 01:27 PM, Petr Viktorin wrote: Hello, This adds managed

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Simo Sorce
On Thu, 2014-09-04 at 15:55 +0200, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014 01:27 PM, Petr Viktorin wrote: Hello,

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Martin Kosek
On 09/04/2014 04:10 PM, Alexander Bokovoy wrote: ... createTimestamp is operational attribute and is synthesized by slapi-nis, there is no problem allowing access to it. I think we can allow following operational attributes: createTimestamp, modifyTimestamp, entryUSN, creatorsName,

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Ludwig Krispenz
On 09/04/2014 04:38 PM, Martin Kosek wrote: On 09/04/2014 04:10 PM, Alexander Bokovoy wrote: ... createTimestamp is operational attribute and is synthesized by slapi-nis, there is no problem allowing access to it. I think we can allow following operational attributes: createTimestamp,

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Jakub Hrozek
On Thu, Sep 04, 2014 at 10:30:11AM -0400, Simo Sorce wrote: On Thu, 2014-09-04 at 15:55 +0200, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Alexander Bokovoy
On Thu, 04 Sep 2014, Simo Sorce wrote: On Thu, 2014-09-04 at 15:55 +0200, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Simo Sorce
On Thu, 2014-09-04 at 18:10 +0300, Alexander Bokovoy wrote: On Thu, 04 Sep 2014, Simo Sorce wrote: On Thu, 2014-09-04 at 15:55 +0200, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote:

[Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-03 Thread Petr Viktorin
Hello, This adds managed read permissions to the compat tree. For users it grants anonymous access; authenticated users can read groups, hosts and netgroups. I'm unsure if this is what we want to do for groups, but Read Group Membership is only granted to authenticated users by default, and

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-03 Thread Petr Viktorin
On 09/03/2014 01:27 PM, Petr Viktorin wrote: Hello, This adds managed read permissions to the compat tree. For users it grants anonymous access; authenticated users can read groups, hosts and netgroups. I'm unsure if this is what we want to do for groups, but Read Group Membership is only

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-03 Thread Petr Viktorin
On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014 01:27 PM, Petr Viktorin wrote: Hello, This adds managed read permissions to the compat tree. For users it grants anonymous access; authenticated users can read groups, hosts and netgroups. I'm unsure if this is what we want to do for

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-03 Thread Simo Sorce
On Wed, 2014-09-03 at 13:27 +0200, Petr Viktorin wrote: Hello, This adds managed read permissions to the compat tree. For users it grants anonymous access; authenticated users can read groups, hosts and netgroups. I'm unsure if this is what we want to do for groups, but Read Group

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-03 Thread Petr Viktorin
On 09/03/2014 04:51 PM, Simo Sorce wrote: On Wed, 2014-09-03 at 13:27 +0200, Petr Viktorin wrote: Hello, This adds managed read permissions to the compat tree. For users it grants anonymous access; authenticated users can read groups, hosts and netgroups. I'm unsure if this is what we want to

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-03 Thread Martin Kosek
On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014 01:27 PM, Petr Viktorin wrote: Hello, This adds managed read permissions to the compat tree. For users it grants anonymous access; authenticated users can read groups, hosts and