Re: [Freeipa-devel] Handling of krbPrincpalExpiration in default ACI

2014-01-08 Thread Simo Sorce
On Wed, 2014-01-08 at 16:41 +0100, Tomas Babej wrote: > On 01/08/2014 04:19 PM, Simo Sorce wrote: > > On Wed, 2014-01-08 at 15:49 +0100, Petr Viktorin wrote: > >> On 01/08/2014 03:43 PM, Simo Sorce wrote: > >>> On Wed, 2014-01-08 at 09:19 -0500, Simo Sorce wrote: > On Wed, 2014-01-08 at 13:42

Re: [Freeipa-devel] Handling of krbPrincpalExpiration in default ACI

2014-01-08 Thread Tomas Babej
On 01/08/2014 04:19 PM, Simo Sorce wrote: > On Wed, 2014-01-08 at 15:49 +0100, Petr Viktorin wrote: >> On 01/08/2014 03:43 PM, Simo Sorce wrote: >>> On Wed, 2014-01-08 at 09:19 -0500, Simo Sorce wrote: On Wed, 2014-01-08 at 13:42 +0100, Tomas Babej wrote: > Hi, > > I'm working on

Re: [Freeipa-devel] Handling of krbPrincpalExpiration in default ACI

2014-01-08 Thread Martin Kosek
On 01/08/2014 04:19 PM, Simo Sorce wrote: > On Wed, 2014-01-08 at 15:49 +0100, Petr Viktorin wrote: >> On 01/08/2014 03:43 PM, Simo Sorce wrote: >>> On Wed, 2014-01-08 at 09:19 -0500, Simo Sorce wrote: On Wed, 2014-01-08 at 13:42 +0100, Tomas Babej wrote: > Hi, > > I'm working on e

Re: [Freeipa-devel] Handling of krbPrincpalExpiration in default ACI

2014-01-08 Thread Simo Sorce
On Wed, 2014-01-08 at 15:49 +0100, Petr Viktorin wrote: > On 01/08/2014 03:43 PM, Simo Sorce wrote: > > On Wed, 2014-01-08 at 09:19 -0500, Simo Sorce wrote: > >> On Wed, 2014-01-08 at 13:42 +0100, Tomas Babej wrote: > >>> Hi, > >>> > >>> I'm working on exposing the krbPrincipalExpiration attribute

Re: [Freeipa-devel] Handling of krbPrincpalExpiration in default ACI

2014-01-08 Thread Tomas Babej
On 01/08/2014 03:46 PM, Rob Crittenden wrote: > Simo Sorce wrote: >> On Wed, 2014-01-08 at 09:19 -0500, Simo Sorce wrote: >>> On Wed, 2014-01-08 at 13:42 +0100, Tomas Babej wrote: Hi, I'm working on exposing the krbPrincipalExpiration attribute in the CLI (https://fedoraho

Re: [Freeipa-devel] Handling of krbPrincpalExpiration in default ACI

2014-01-08 Thread Martin Kosek
On 01/08/2014 03:54 PM, Tomas Babej wrote: > > On 01/08/2014 03:46 PM, Rob Crittenden wrote: >> Simo Sorce wrote: >>> On Wed, 2014-01-08 at 09:19 -0500, Simo Sorce wrote: On Wed, 2014-01-08 at 13:42 +0100, Tomas Babej wrote: > Hi, > > I'm working on exposing the krbPrincipalExpira

Re: [Freeipa-devel] Handling of krbPrincpalExpiration in default ACI

2014-01-08 Thread Petr Viktorin
On 01/08/2014 03:43 PM, Simo Sorce wrote: On Wed, 2014-01-08 at 09:19 -0500, Simo Sorce wrote: On Wed, 2014-01-08 at 13:42 +0100, Tomas Babej wrote: Hi, I'm working on exposing the krbPrincipalExpiration attribute in the CLI (https://fedorahosted.org/freeipa/ticket/3306). However, this attribu

Re: [Freeipa-devel] Handling of krbPrincpalExpiration in default ACI

2014-01-08 Thread Martin Kosek
On 01/08/2014 03:46 PM, Rob Crittenden wrote: > Simo Sorce wrote: >> On Wed, 2014-01-08 at 09:19 -0500, Simo Sorce wrote: >>> On Wed, 2014-01-08 at 13:42 +0100, Tomas Babej wrote: Hi, I'm working on exposing the krbPrincipalExpiration attribute in the CLI (https://fedorahosted.o

Re: [Freeipa-devel] Handling of krbPrincpalExpiration in default ACI

2014-01-08 Thread Rob Crittenden
Simo Sorce wrote: On Wed, 2014-01-08 at 09:19 -0500, Simo Sorce wrote: On Wed, 2014-01-08 at 13:42 +0100, Tomas Babej wrote: Hi, I'm working on exposing the krbPrincipalExpiration attribute in the CLI (https://fedorahosted.org/freeipa/ticket/3306). However, this attribute is exempted from the

Re: [Freeipa-devel] Handling of krbPrincpalExpiration in default ACI

2014-01-08 Thread Simo Sorce
On Wed, 2014-01-08 at 09:19 -0500, Simo Sorce wrote: > On Wed, 2014-01-08 at 13:42 +0100, Tomas Babej wrote: > > Hi, > > > > I'm working on exposing the krbPrincipalExpiration attribute in the CLI > > (https://fedorahosted.org/freeipa/ticket/3306). However, this attribute > > is exempted from the

Re: [Freeipa-devel] Handling of krbPrincpalExpiration in default ACI

2014-01-08 Thread Simo Sorce
On Wed, 2014-01-08 at 13:42 +0100, Tomas Babej wrote: > Hi, > > I'm working on exposing the krbPrincipalExpiration attribute in the CLI > (https://fedorahosted.org/freeipa/ticket/3306). However, this attribute > is exempted from the default ACL "Admin can manage any entry" > (install/share/default

[Freeipa-devel] Handling of krbPrincpalExpiration in default ACI

2014-01-08 Thread Tomas Babej
Hi, I'm working on exposing the krbPrincipalExpiration attribute in the CLI (https://fedorahosted.org/freeipa/ticket/3306). However, this attribute is exempted from the default ACL "Admin can manage any entry" (install/share/default-aci.ldif +8). Now, we have several options: 1.) remove it from b