Re: [Freeipa-devel] #4054 - ACIs for managing own hosts, users, groups...

2014-05-28 Thread Martin Kosek
On 04/16/2014 03:42 PM, Simo Sorce wrote: > On Wed, 2014-04-16 at 14:55 +0200, Martin Kosek wrote: >> On 04/16/2014 02:49 PM, Petr Viktorin wrote: >>> On 04/16/2014 02:45 PM, Simo Sorce wrote: On Wed, 2014-04-16 at 10:20 +0200, Petr Viktorin wrote: > On 04/16/2014 10:02 AM, Martin Kosek wr

Re: [Freeipa-devel] #4054 - ACIs for managing own hosts, users, groups...

2014-04-16 Thread Simo Sorce
On Wed, 2014-04-16 at 14:55 +0200, Martin Kosek wrote: > On 04/16/2014 02:49 PM, Petr Viktorin wrote: > > On 04/16/2014 02:45 PM, Simo Sorce wrote: > >> On Wed, 2014-04-16 at 10:20 +0200, Petr Viktorin wrote: > >>> On 04/16/2014 10:02 AM, Martin Kosek wrote: > I was looking into ticket >

Re: [Freeipa-devel] #4054 - ACIs for managing own hosts, users, groups...

2014-04-16 Thread Martin Kosek
On 04/16/2014 02:49 PM, Petr Viktorin wrote: > On 04/16/2014 02:45 PM, Simo Sorce wrote: >> On Wed, 2014-04-16 at 10:20 +0200, Petr Viktorin wrote: >>> On 04/16/2014 10:02 AM, Martin Kosek wrote: I was looking into ticket https://fedorahosted.org/freeipa/ticket/4054 and experimenting

Re: [Freeipa-devel] #4054 - ACIs for managing own hosts, users, groups...

2014-04-16 Thread Petr Viktorin
On 04/16/2014 02:45 PM, Simo Sorce wrote: On Wed, 2014-04-16 at 10:20 +0200, Petr Viktorin wrote: On 04/16/2014 10:02 AM, Martin Kosek wrote: I was looking into ticket https://fedorahosted.org/freeipa/ticket/4054 and experimenting with ACIs allowing privileged users to manage only their own LDA

Re: [Freeipa-devel] #4054 - ACIs for managing own hosts, users, groups...

2014-04-16 Thread Simo Sorce
On Wed, 2014-04-16 at 13:12 +0200, Martin Kosek wrote: > On 04/16/2014 10:35 AM, Jan Cholasta wrote: > > On 16.4.2014 10:20, Petr Viktorin wrote: > >> On 04/16/2014 10:02 AM, Martin Kosek wrote: > >>> I was looking into ticket > >>> https://fedorahosted.org/freeipa/ticket/4054 > >>> and experimenti

Re: [Freeipa-devel] #4054 - ACIs for managing own hosts, users, groups...

2014-04-16 Thread Simo Sorce
On Wed, 2014-04-16 at 10:20 +0200, Petr Viktorin wrote: > On 04/16/2014 10:02 AM, Martin Kosek wrote: > > I was looking into ticket > > https://fedorahosted.org/freeipa/ticket/4054 > > and experimenting with ACIs allowing privileged users to manage only > > their own LDAP objects. > > > > As alread

Re: [Freeipa-devel] #4054 - ACIs for managing own hosts, users, groups...

2014-04-16 Thread Simo Sorce
On Wed, 2014-04-16 at 10:02 +0200, Martin Kosek wrote: > I was looking into ticket > https://fedorahosted.org/freeipa/ticket/4054 > and experimenting with ACIs allowing privileged users to manage only their > own > LDAP objects. > > As already proposed in the Bugzilla, I had success with followi

Re: [Freeipa-devel] #4054 - ACIs for managing own hosts, users, groups...

2014-04-16 Thread Martin Kosek
On 04/16/2014 10:35 AM, Jan Cholasta wrote: > On 16.4.2014 10:20, Petr Viktorin wrote: >> On 04/16/2014 10:02 AM, Martin Kosek wrote: >>> I was looking into ticket >>> https://fedorahosted.org/freeipa/ticket/4054 >>> and experimenting with ACIs allowing privileged users to manage only >>> their own

Re: [Freeipa-devel] #4054 - ACIs for managing own hosts, users, groups...

2014-04-16 Thread Jan Cholasta
On 16.4.2014 10:20, Petr Viktorin wrote: On 04/16/2014 10:02 AM, Martin Kosek wrote: I was looking into ticket https://fedorahosted.org/freeipa/ticket/4054 and experimenting with ACIs allowing privileged users to manage only their own LDAP objects. As already proposed in the Bugzilla, I had suc

Re: [Freeipa-devel] #4054 - ACIs for managing own hosts, users, groups...

2014-04-16 Thread Petr Viktorin
On 04/16/2014 10:02 AM, Martin Kosek wrote: I was looking into ticket https://fedorahosted.org/freeipa/ticket/4054 and experimenting with ACIs allowing privileged users to manage only their own LDAP objects. As already proposed in the Bugzilla, I had success with following ACIs: ~~~

[Freeipa-devel] #4054 - ACIs for managing own hosts, users, groups...

2014-04-16 Thread Martin Kosek
I was looking into ticket https://fedorahosted.org/freeipa/ticket/4054 and experimenting with ACIs allowing privileged users to manage only their own LDAP objects. As already proposed in the Bugzilla, I had success with following ACIs: # ldapmodify -h `hostname` -D "cn=Directo