Re: [Freeipa-devel] [PATCH] 942 limit resetting admins passwords

2012-02-20 Thread Martin Kosek
On Wed, 2012-02-08 at 15:12 +0100, Martin Kosek wrote: > On Wed, 2012-02-08 at 08:57 -0500, Simo Sorce wrote: > > On Wed, 2012-02-08 at 13:28 +0100, Martin Kosek wrote: > > > On Tue, 2012-02-07 at 18:19 -0500, Rob Crittenden wrote: > > > > Don't allow the 'change user password' permission to be abl

Re: [Freeipa-devel] [PATCH] 942 limit resetting admins passwords

2012-02-08 Thread Martin Kosek
On Wed, 2012-02-08 at 08:57 -0500, Simo Sorce wrote: > On Wed, 2012-02-08 at 13:28 +0100, Martin Kosek wrote: > > On Tue, 2012-02-07 at 18:19 -0500, Rob Crittenden wrote: > > > Don't allow the 'change user password' permission to be able to reset > > > the password of the admins group. > > > > >

Re: [Freeipa-devel] [PATCH] 942 limit resetting admins passwords

2012-02-08 Thread Simo Sorce
On Wed, 2012-02-08 at 13:28 +0100, Martin Kosek wrote: > On Tue, 2012-02-07 at 18:19 -0500, Rob Crittenden wrote: > > Don't allow the 'change user password' permission to be able to reset > > the password of the admins group. > > > > rob > > NACK > > The admin filter works OK, user fbar (in hel

Re: [Freeipa-devel] [PATCH] 942 limit resetting admins passwords

2012-02-08 Thread Martin Kosek
On Tue, 2012-02-07 at 18:19 -0500, Rob Crittenden wrote: > Don't allow the 'change user password' permission to be able to reset > the password of the admins group. > > rob NACK The admin filter works OK, user fbar (in helpdesk role) is now not able to change admin's password: # klist Ticket c

[Freeipa-devel] [PATCH] 942 limit resetting admins passwords

2012-02-07 Thread Rob Crittenden
Don't allow the 'change user password' permission to be able to reset the password of the admins group. rob freeipa-rcrit-942-aci.patch Description: application/mbox ___ Freeipa-devel mailing list Freeipa-devel@redhat.com https://www.redhat.com/mailm