Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-10 Thread Petr Viktorin
On 04/09/2014 05:17 PM, Martin Kosek wrote: On 04/09/2014 04:54 PM, Petr Viktorin wrote: The meta-permissions. :-) Read access is given to all authenticated users. Reading membership info (i.e. privileges) is split into a separate permission. Another permission is added that allows read

Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-10 Thread Martin Kosek
On 04/10/2014 01:46 PM, Petr Viktorin wrote: On 04/09/2014 05:17 PM, Martin Kosek wrote: On 04/09/2014 04:54 PM, Petr Viktorin wrote: The meta-permissions. :-) Read access is given to all authenticated users. Reading membership info (i.e. privileges) is split into a separate permission.

Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-10 Thread Petr Viktorin
On 04/10/2014 02:58 PM, Martin Kosek wrote: On 04/10/2014 01:46 PM, Petr Viktorin wrote: On 04/09/2014 05:17 PM, Martin Kosek wrote: On 04/09/2014 04:54 PM, Petr Viktorin wrote: The meta-permissions. :-) Read access is given to all authenticated users. Reading membership info (i.e.

Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-10 Thread Martin Kosek
On 04/10/2014 03:02 PM, Petr Viktorin wrote: On 04/10/2014 02:58 PM, Martin Kosek wrote: On 04/10/2014 01:46 PM, Petr Viktorin wrote: On 04/09/2014 05:17 PM, Martin Kosek wrote: On 04/09/2014 04:54 PM, Petr Viktorin wrote: The meta-permissions. :-) Read access is given to all

Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-10 Thread Simo Sorce
On Thu, 2014-04-10 at 15:02 +0200, Petr Viktorin wrote: On 04/10/2014 02:58 PM, Martin Kosek wrote: On 04/10/2014 01:46 PM, Petr Viktorin wrote: On 04/09/2014 05:17 PM, Martin Kosek wrote: On 04/09/2014 04:54 PM, Petr Viktorin wrote: The meta-permissions. :-) Read access is given

Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-10 Thread Martin Kosek
On 04/10/2014 03:07 PM, Simo Sorce wrote: On Thu, 2014-04-10 at 15:02 +0200, Petr Viktorin wrote: On 04/10/2014 02:58 PM, Martin Kosek wrote: On 04/10/2014 01:46 PM, Petr Viktorin wrote: On 04/09/2014 05:17 PM, Martin Kosek wrote: On 04/09/2014 04:54 PM, Petr Viktorin wrote: The

Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-10 Thread Petr Viktorin
On 04/10/2014 03:07 PM, Martin Kosek wrote: On 04/10/2014 03:02 PM, Petr Viktorin wrote: On 04/10/2014 02:58 PM, Martin Kosek wrote: On 04/10/2014 01:46 PM, Petr Viktorin wrote: On 04/09/2014 05:17 PM, Martin Kosek wrote: On 04/09/2014 04:54 PM, Petr Viktorin wrote: The meta-permissions.

Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-10 Thread Martin Kosek
On 04/10/2014 03:10 PM, Petr Viktorin wrote: On 04/10/2014 03:07 PM, Martin Kosek wrote: On 04/10/2014 03:02 PM, Petr Viktorin wrote: On 04/10/2014 02:58 PM, Martin Kosek wrote: On 04/10/2014 01:46 PM, Petr Viktorin wrote: On 04/09/2014 05:17 PM, Martin Kosek wrote: On 04/09/2014 04:54 PM,

[Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-09 Thread Petr Viktorin
The meta-permissions. Read access is given to all authenticated users. Reading membership info (i.e. privileges) is split into a separate permission. Another permission is added that allows read access to all ACIs. If we don't want to open that up for everyone, I could limit this to only

Re: [Freeipa-devel] [PATCH] 0513 Add managed read permissions to permission

2014-04-09 Thread Martin Kosek
On 04/09/2014 04:54 PM, Petr Viktorin wrote: The meta-permissions. :-) Read access is given to all authenticated users. Reading membership info (i.e. privileges) is split into a separate permission. Another permission is added that allows read access to all ACIs. If we don't want to open