Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Alexander Bokovoy
On Thu, 04 Sep 2014, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014 01:27 PM, Petr Viktorin wrote: Hello, This adds managed

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Alexander Bokovoy
On Fri, 05 Sep 2014, Alexander Bokovoy wrote: On Thu, 04 Sep 2014, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014 01:27 PM,

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Martin Kosek
On 09/05/2014 09:03 AM, Alexander Bokovoy wrote: On Fri, 05 Sep 2014, Alexander Bokovoy wrote: On Thu, 04 Sep 2014, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Martin Kosek
On 09/04/2014 04:44 PM, Ludwig Krispenz wrote: On 09/04/2014 04:38 PM, Martin Kosek wrote: On 09/04/2014 04:10 PM, Alexander Bokovoy wrote: ... createTimestamp is operational attribute and is synthesized by slapi-nis, there is no problem allowing access to it. I think we can allow

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Alexander Bokovoy
On Fri, 05 Sep 2014, Martin Kosek wrote: On 09/04/2014 04:44 PM, Ludwig Krispenz wrote: On 09/04/2014 04:38 PM, Martin Kosek wrote: On 09/04/2014 04:10 PM, Alexander Bokovoy wrote: ... createTimestamp is operational attribute and is synthesized by slapi-nis, there is no problem allowing

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Petr Viktorin
On 09/05/2014 09:18 AM, Martin Kosek wrote: On 09/05/2014 09:03 AM, Alexander Bokovoy wrote: On Fri, 05 Sep 2014, Alexander Bokovoy wrote: On Thu, 04 Sep 2014, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Alexander Bokovoy
On Fri, 05 Sep 2014, Petr Viktorin wrote: On 09/05/2014 09:18 AM, Martin Kosek wrote: On 09/05/2014 09:03 AM, Alexander Bokovoy wrote: On Fri, 05 Sep 2014, Alexander Bokovoy wrote: On Thu, 04 Sep 2014, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014,

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Petr Viktorin
On 09/05/2014 01:34 PM, Alexander Bokovoy wrote: On Fri, 05 Sep 2014, Petr Viktorin wrote: On 09/05/2014 09:18 AM, Martin Kosek wrote: ... Thanks! Looks sane to me. We would just need to remove Views related ACIs for the 4.0.x version that we will need for today. Thanks indeed! Here is the

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Simo Sorce
On Fri, 2014-09-05 at 12:12 +0300, Alexander Bokovoy wrote: On Fri, 05 Sep 2014, Martin Kosek wrote: On 09/04/2014 04:44 PM, Ludwig Krispenz wrote: On 09/04/2014 04:38 PM, Martin Kosek wrote: On 09/04/2014 04:10 PM, Alexander Bokovoy wrote: ... createTimestamp is operational attribute

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-05 Thread Petr Viktorin
On 09/05/2014 01:51 PM, Petr Viktorin wrote: On 09/05/2014 01:34 PM, Alexander Bokovoy wrote: On Fri, 05 Sep 2014, Petr Viktorin wrote: On 09/05/2014 09:18 AM, Martin Kosek wrote: ... Thanks! Looks sane to me. We would just need to remove Views related ACIs for the 4.0.x version that we will

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Alexander Bokovoy
On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014 01:27 PM, Petr Viktorin wrote: Hello, This adds managed read permissions to the compat tree. For users it grants anonymous access; authenticated

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Martin Kosek
On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014 01:27 PM, Petr Viktorin wrote: Hello, This adds managed read permissions to the compat tree. For

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Alexander Bokovoy
On Thu, 04 Sep 2014, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014 01:27 PM, Petr Viktorin wrote: Hello, This adds managed

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Simo Sorce
On Thu, 2014-09-04 at 15:55 +0200, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014 01:27 PM, Petr Viktorin wrote: Hello,

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Martin Kosek
On 09/04/2014 04:10 PM, Alexander Bokovoy wrote: ... createTimestamp is operational attribute and is synthesized by slapi-nis, there is no problem allowing access to it. I think we can allow following operational attributes: createTimestamp, modifyTimestamp, entryUSN, creatorsName,

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Ludwig Krispenz
On 09/04/2014 04:38 PM, Martin Kosek wrote: On 09/04/2014 04:10 PM, Alexander Bokovoy wrote: ... createTimestamp is operational attribute and is synthesized by slapi-nis, there is no problem allowing access to it. I think we can allow following operational attributes: createTimestamp,

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Jakub Hrozek
On Thu, Sep 04, 2014 at 10:30:11AM -0400, Simo Sorce wrote: On Thu, 2014-09-04 at 15:55 +0200, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Alexander Bokovoy
On Thu, 04 Sep 2014, Simo Sorce wrote: On Thu, 2014-09-04 at 15:55 +0200, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-04 Thread Simo Sorce
On Thu, 2014-09-04 at 18:10 +0300, Alexander Bokovoy wrote: On Thu, 04 Sep 2014, Simo Sorce wrote: On Thu, 2014-09-04 at 15:55 +0200, Martin Kosek wrote: On 09/04/2014 02:40 PM, Alexander Bokovoy wrote: On Wed, 03 Sep 2014, Martin Kosek wrote: On 09/03/2014 03:15 PM, Petr Viktorin wrote:

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-03 Thread Petr Viktorin
On 09/03/2014 01:27 PM, Petr Viktorin wrote: Hello, This adds managed read permissions to the compat tree. For users it grants anonymous access; authenticated users can read groups, hosts and netgroups. I'm unsure if this is what we want to do for groups, but Read Group Membership is only

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-03 Thread Petr Viktorin
On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014 01:27 PM, Petr Viktorin wrote: Hello, This adds managed read permissions to the compat tree. For users it grants anonymous access; authenticated users can read groups, hosts and netgroups. I'm unsure if this is what we want to do for

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-03 Thread Simo Sorce
On Wed, 2014-09-03 at 13:27 +0200, Petr Viktorin wrote: Hello, This adds managed read permissions to the compat tree. For users it grants anonymous access; authenticated users can read groups, hosts and netgroups. I'm unsure if this is what we want to do for groups, but Read Group

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-03 Thread Petr Viktorin
On 09/03/2014 04:51 PM, Simo Sorce wrote: On Wed, 2014-09-03 at 13:27 +0200, Petr Viktorin wrote: Hello, This adds managed read permissions to the compat tree. For users it grants anonymous access; authenticated users can read groups, hosts and netgroups. I'm unsure if this is what we want to

Re: [Freeipa-devel] [PATCH] 0640 Add managed read permissions for compat tree

2014-09-03 Thread Martin Kosek
On 09/03/2014 03:15 PM, Petr Viktorin wrote: On 09/03/2014 02:27 PM, Petr Viktorin wrote: On 09/03/2014 01:27 PM, Petr Viktorin wrote: Hello, This adds managed read permissions to the compat tree. For users it grants anonymous access; authenticated users can read groups, hosts and