Re: [Freeipa-devel] [PATCH] 549 remove reliance on admin user

2010-10-01 Thread Rob Crittenden

Adam Young wrote:

On 09/29/2010 01:55 PM, Rob Crittenden wrote:

Change the finals aci so that the login admin is no longer special.
The group admins is now controls the super-user group.

rob


___
Freeipa-devel mailing list
Freeipa-devel@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-devel

Do I read it right that now you can delete an admin user? What if there
is only one Admin user, and you delete that?


Yes, you can now delete the admin user. If you delete it and have no 
more admins you will have to use the Directory Manager account to create 
a new admin, or if you have a user in the group management role they can 
add a new admins user.


rob

___
Freeipa-devel mailing list
Freeipa-devel@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-devel


Re: [Freeipa-devel] [PATCH] 549 remove reliance on admin user

2010-10-01 Thread Adam Young

On 10/01/2010 01:41 PM, Rob Crittenden wrote:

Adam Young wrote:

On 09/29/2010 01:55 PM, Rob Crittenden wrote:

Change the finals aci so that the login admin is no longer special.
The group admins is now controls the super-user group.

rob


___
Freeipa-devel mailing list
Freeipa-devel@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-devel

Do I read it right that now you can delete an admin user? What if there
is only one Admin user, and you delete that?


Yes, you can now delete the admin user. If you delete it and have no 
more admins you will have to use the Directory Manager account to 
create a new admin, or if you have a user in the group management role 
they can add a new admins user.


rob

ACK,
please make sure  the above info makes it in the the docs.

___
Freeipa-devel mailing list
Freeipa-devel@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-devel


Re: [Freeipa-devel] [PATCH] 549 remove reliance on admin user

2010-10-01 Thread Dmitri Pal
Adam Young wrote:
 On 10/01/2010 01:41 PM, Rob Crittenden wrote:
 Adam Young wrote:
 On 09/29/2010 01:55 PM, Rob Crittenden wrote:
 Change the finals aci so that the login admin is no longer special.
 The group admins is now controls the super-user group.

 rob


 ___
 Freeipa-devel mailing list
 Freeipa-devel@redhat.com
 https://www.redhat.com/mailman/listinfo/freeipa-devel
 Do I read it right that now you can delete an admin user? What if there
 is only one Admin user, and you delete that?

 Yes, you can now delete the admin user. If you delete it and have no
 more admins you will have to use the Directory Manager account to
 create a new admin, or if you have a user in the group management
 role they can add a new admins user.

 rob
 ACK,
 please make sure  the above info makes it in the the docs.

I will open a BZ


 ___
 Freeipa-devel mailing list
 Freeipa-devel@redhat.com
 https://www.redhat.com/mailman/listinfo/freeipa-devel




-- 
Thank you,
Dmitri Pal

Engineering Manager IPA project,
Red Hat Inc.


---
Looking to carve out IT costs?
www.redhat.com/carveoutcosts/

___
Freeipa-devel mailing list
Freeipa-devel@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-devel


Re: [Freeipa-devel] [PATCH] 549 remove reliance on admin user

2010-09-29 Thread Adam Young

On 09/29/2010 01:55 PM, Rob Crittenden wrote:
Change the finals aci so that the login admin is no longer special. 
The group admins is now controls the super-user group.


rob


___
Freeipa-devel mailing list
Freeipa-devel@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-devel
Do I read it right that now you can delete an admin user?  What if there 
is only one Admin user, and you delete that?
___
Freeipa-devel mailing list
Freeipa-devel@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-devel