[Freeipa-users] Re: ACIs for replication status monitoring

2023-04-25 Thread Sam Morris via FreeIPA-users
On Mon, Apr 24, 2023 at 03:54:30PM -0400, Rob Crittenden via FreeIPA-users wrote: > Sam Morris wrote: > > On Mon, Apr 24, 2023 at 12:07:16PM -0400, Rob Crittenden via FreeIPA-users > > wrote: > >>> However, this attribute can be read from the second search! Although > >>> it's not included in the

[Freeipa-users] Re: ACIs for replication status monitoring

2023-04-24 Thread Rob Crittenden via FreeIPA-users
Sam Morris wrote: > On Mon, Apr 24, 2023 at 12:07:16PM -0400, Rob Crittenden via FreeIPA-users > wrote: >>> However, this attribute can be read from the second search! Although >>> it's not included in the results when 'ALL' attributes are requested, >>> explicitly adding it to the search query wo

[Freeipa-users] Re: ACIs for replication status monitoring

2023-04-24 Thread Sam Morris via FreeIPA-users
On Mon, Apr 24, 2023 at 12:07:16PM -0400, Rob Crittenden via FreeIPA-users wrote: > > However, this attribute can be read from the second search! Although > > it's not included in the results when 'ALL' attributes are requested, > > explicitly adding it to the search query works fine: > > The thir

[Freeipa-users] Re: ACIs for replication status monitoring

2023-04-24 Thread Rob Crittenden via FreeIPA-users
Sam Morris via FreeIPA-users wrote: > I've created a system account for replication status monitoring: > > uid=repl-mon,cn=sysaccounts,cn=etc,dc=ipa,dc=example,dc=com > > ... and I've added it to the permissions: > > "cn=Read Replication > Agreements,cn=permissions,cn=pbac,dc=ipa,dc=example,dc=