Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-29 Thread Simo Sorce
On Tue, 2014-04-29 at 15:10 +0200, Martin Kosek wrote: > On 04/29/2014 02:48 PM, Simo Sorce wrote: > > On Tue, 2014-04-29 at 14:21 +0200, Martin Kosek wrote: > >> On 04/29/2014 01:03 PM, Petr Viktorin wrote: > >>> On 04/24/2014 11:35 AM, Martin Kosek wrote: > On 04/23/2014 10:53 PM, Martin Kos

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-29 Thread Martin Kosek
On 04/29/2014 02:48 PM, Simo Sorce wrote: > On Tue, 2014-04-29 at 14:21 +0200, Martin Kosek wrote: >> On 04/29/2014 01:03 PM, Petr Viktorin wrote: >>> On 04/24/2014 11:35 AM, Martin Kosek wrote: On 04/23/2014 10:53 PM, Martin Kosek wrote: > On 04/23/2014 08:07 PM, Simo Sorce wrote: >>> [..

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-29 Thread Simo Sorce
On Tue, 2014-04-29 at 14:21 +0200, Martin Kosek wrote: > On 04/29/2014 01:03 PM, Petr Viktorin wrote: > > On 04/24/2014 11:35 AM, Martin Kosek wrote: > >> On 04/23/2014 10:53 PM, Martin Kosek wrote: > >>> On 04/23/2014 08:07 PM, Simo Sorce wrote: > > [...] > > I know, we may need to provi

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-29 Thread Martin Kosek
On 04/29/2014 01:03 PM, Petr Viktorin wrote: > On 04/24/2014 11:35 AM, Martin Kosek wrote: >> On 04/23/2014 10:53 PM, Martin Kosek wrote: >>> On 04/23/2014 08:07 PM, Simo Sorce wrote: > [...] I know, we may need to provide another permission admins can use to turn on anonymous search

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-29 Thread Petr Viktorin
On 04/24/2014 11:35 AM, Martin Kosek wrote: On 04/23/2014 10:53 PM, Martin Kosek wrote: On 04/23/2014 08:07 PM, Simo Sorce wrote: [...] I know, we may need to provide another permission admins can use to turn on anonymous searches for those attributes too. We may also decide that on upgrade v

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-24 Thread Martin Kosek
On 04/23/2014 10:53 PM, Martin Kosek wrote: > On 04/23/2014 08:07 PM, Simo Sorce wrote: >> On Wed, 2014-04-23 at 18:19 +0200, Martin Kosek wrote: >>> On 04/23/2014 05:21 PM, Simo Sorce wrote: On Wed, 2014-04-23 at 16:37 +0200, Martin Kosek wrote: > On 04/17/2014 01:45 PM, Petr Viktorin wro

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-23 Thread Martin Kosek
On 04/23/2014 08:07 PM, Simo Sorce wrote: On Wed, 2014-04-23 at 18:19 +0200, Martin Kosek wrote: On 04/23/2014 05:21 PM, Simo Sorce wrote: On Wed, 2014-04-23 at 16:37 +0200, Martin Kosek wrote: On 04/17/2014 01:45 PM, Petr Viktorin wrote: On 04/16/2014 03:41 PM, Simo Sorce wrote: On Wed, 201

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-23 Thread Simo Sorce
On Wed, 2014-04-23 at 18:19 +0200, Martin Kosek wrote: > On 04/23/2014 05:21 PM, Simo Sorce wrote: > > On Wed, 2014-04-23 at 16:37 +0200, Martin Kosek wrote: > >> On 04/17/2014 01:45 PM, Petr Viktorin wrote: > >>> On 04/16/2014 03:41 PM, Simo Sorce wrote: > On Wed, 2014-04-16 at 15:08 +0200, M

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-23 Thread Martin Kosek
On 04/23/2014 05:21 PM, Simo Sorce wrote: > On Wed, 2014-04-23 at 16:37 +0200, Martin Kosek wrote: >> On 04/17/2014 01:45 PM, Petr Viktorin wrote: >>> On 04/16/2014 03:41 PM, Simo Sorce wrote: On Wed, 2014-04-16 at 15:08 +0200, Martin Kosek wrote: > On 04/15/2014 04:55 PM, Petr Viktorin wr

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-23 Thread Simo Sorce
On Wed, 2014-04-23 at 16:37 +0200, Martin Kosek wrote: > On 04/17/2014 01:45 PM, Petr Viktorin wrote: > > On 04/16/2014 03:41 PM, Simo Sorce wrote: > >> On Wed, 2014-04-16 at 15:08 +0200, Martin Kosek wrote: > >>> On 04/15/2014 04:55 PM, Petr Viktorin wrote: > Hello, > At Devconf, we deci

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-23 Thread Martin Kosek
On 04/17/2014 01:45 PM, Petr Viktorin wrote: > On 04/16/2014 03:41 PM, Simo Sorce wrote: >> On Wed, 2014-04-16 at 15:08 +0200, Martin Kosek wrote: >>> On 04/15/2014 04:55 PM, Petr Viktorin wrote: Hello, At Devconf, we decided what most of the default read permissions should look >>>

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-17 Thread Petr Viktorin
On 04/16/2014 03:41 PM, Simo Sorce wrote: On Wed, 2014-04-16 at 15:08 +0200, Martin Kosek wrote: On 04/15/2014 04:55 PM, Petr Viktorin wrote: Hello, At Devconf, we decided what most of the default read permissions should look like, but we did not get to user. Here is a draft of 4 read permissio

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-16 Thread Martin Kosek
On 04/16/2014 03:41 PM, Simo Sorce wrote: > On Wed, 2014-04-16 at 15:08 +0200, Martin Kosek wrote: >> On 04/15/2014 04:55 PM, Petr Viktorin wrote: ... >>> [mepOriginEntry] >>> mepManagedEntry >> >> This is used to bind user to it's private group. We use it for example in >> group-detach command

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-16 Thread Simo Sorce
On Wed, 2014-04-16 at 15:08 +0200, Martin Kosek wrote: > On 04/15/2014 04:55 PM, Petr Viktorin wrote: > > Hello, > > At Devconf, we decided what most of the default read permissions should look > > like, but we did not get to user. > > Here is a draft of 4 read permissions. Please comment. > > > >

Re: [Freeipa-devel] Draft: Read permissions for user

2014-04-16 Thread Martin Kosek
On 04/15/2014 04:55 PM, Petr Viktorin wrote: > Hello, > At Devconf, we decided what most of the default read permissions should look > like, but we did not get to user. > Here is a draft of 4 read permissions. Please comment. > > > Basic info (anonymous): > [top] > objectclass > [person] >

[Freeipa-devel] Draft: Read permissions for user

2014-04-15 Thread Petr Viktorin
Hello, At Devconf, we decided what most of the default read permissions should look like, but we did not get to user. Here is a draft of 4 read permissions. Please comment. Basic info (anonymous): [top] objectclass [person] cn, sn, description [organizationalPerson] title [inetOrgP