Re: [Freeipa-devel] [PATCH] 916 make category and members mutually exclusive in Sudo

2012-01-18 Thread Martin Kosek
On Tue, 2012-01-17 at 08:59 -0500, Rob Crittenden wrote: Martin Kosek wrote: On Mon, 2012-01-16 at 22:20 -0500, Rob Crittenden wrote: Rob Crittenden wrote: Martin Kosek wrote: On Mon, 2011-12-12 at 17:14 -0500, Rob Crittenden wrote: This patch makes all categories and their equivalent

Re: [Freeipa-devel] [PATCH] 916 make category and members mutually exclusive in Sudo

2012-01-17 Thread Martin Kosek
On Mon, 2012-01-16 at 22:20 -0500, Rob Crittenden wrote: Rob Crittenden wrote: Martin Kosek wrote: On Mon, 2011-12-12 at 17:14 -0500, Rob Crittenden wrote: This patch makes all categories and their equivalent members mutually exclusive like in the HBAC plugin. So if you have usercat='all'

Re: [Freeipa-devel] [PATCH] 916 make category and members mutually exclusive in Sudo

2012-01-17 Thread Rob Crittenden
Martin Kosek wrote: On Mon, 2012-01-16 at 22:20 -0500, Rob Crittenden wrote: Rob Crittenden wrote: Martin Kosek wrote: On Mon, 2011-12-12 at 17:14 -0500, Rob Crittenden wrote: This patch makes all categories and their equivalent members mutually exclusive like in the HBAC plugin. So if you

Re: [Freeipa-devel] [PATCH] 916 make category and members mutually exclusive in Sudo

2012-01-16 Thread Rob Crittenden
Martin Kosek wrote: On Mon, 2011-12-12 at 17:14 -0500, Rob Crittenden wrote: This patch makes all categories and their equivalent members mutually exclusive like in the HBAC plugin. So if you have usercat='all' you can't add users. Added test cases for these as well. I also modified the

[Freeipa-devel] [PATCH] 916 make category and members mutually exclusive in Sudo

2011-12-12 Thread Rob Crittenden
This patch makes all categories and their equivalent members mutually exclusive like in the HBAC plugin. So if you have usercat='all' you can't add users. Added test cases for these as well. I also modified the default list of attributes to include the RunAs attributes. rob From