[Freeipa-users] Re: How to prevent non-admin users of FreeIPA from reading the list of users in the web interface?

2024-04-16 Thread Riccardo Rotondo via FreeIPA-users
Hi Christian and Alexander, considering I'm still in the initial phase of the project I customised the Dockerfile to install the needed package. For those interested here is the fork with the branch: https://github.com/rrotondo/freeipa-container/tree/add-ipa-fas with a custom version for

[Freeipa-users] Re: How to prevent non-admin users of FreeIPA from reading the list of users in the web interface?

2024-04-04 Thread Alexander Bokovoy via FreeIPA-users
On Чцв, 04 кра 2024, Riccardo Rotondo via FreeIPA-users wrote: Hi Alexander, Thank you Alexander, this solution probably fits our needs. My only problem now is the I configured freeipa with docker, and in that image developer didn't include the Fedora Account System plugin for IPA so in the log

[Freeipa-users] Re: How to prevent non-admin users of FreeIPA from reading the list of users in the web interface?

2024-04-04 Thread Christian Heimes via FreeIPA-users
On 04/04/2024 13.24, Riccardo Rotondo via FreeIPA-users wrote: Hi Alexander, Thank you Alexander, this solution probably fits our needs. My only problem now is the I configured freeipa with docker, and in that image developer didn't include the Fedora Account System plugin for IPA so in the

[Freeipa-users] Re: How to prevent non-admin users of FreeIPA from reading the list of users in the web interface?

2024-04-04 Thread Riccardo Rotondo via FreeIPA-users
Hi Alexander, Thank you Alexander, this solution probably fits our needs. My only problem now is the I configured freeipa with docker, and in that image developer didn't include the Fedora Account System plugin for IPA so in the log I found: ERROR in middleware: Uncaught IPA exception:

[Freeipa-users] Re: How to prevent non-admin users of FreeIPA from reading the list of users in the web interface?

2024-03-25 Thread Alexander Bokovoy via FreeIPA-users
On Пан, 25 сак 2024, Riccardo Rotondo via FreeIPA-users wrote: Hi, I'm writing here because, 6 years after, I have the same question cknight previously asked. Any update on that? My users only login to web UI and can't perform ldap search so the only way they can obtain users info it's from

[Freeipa-users] Re: How to prevent non-admin users of FreeIPA from reading the list of users in the web interface?

2024-03-25 Thread Riccardo Rotondo via FreeIPA-users
Hi, I'm writing here because, 6 years after, I have the same question cknight previously asked. Any update on that? My users only login to web UI and can't perform ldap search so the only way they can obtain users info it's from the "Users" page ("#/e/user/details/userame") I understand

[Freeipa-users] Re: How to prevent non-admin users of FreeIPA from reading the list of users in the web interface?

2018-12-11 Thread Alexander Bokovoy via FreeIPA-users
On ti, 11 joulu 2018, cdknight via FreeIPA-users wrote: Thanks for the responses. Therefore, I will instead have to restrict access to the Web UI either by creating an HBAC rule (this is my understanding of what to do), and instead allowing them access a secondary self-service UI like

[Freeipa-users] Re: How to prevent non-admin users of FreeIPA from reading the list of users in the web interface?

2018-12-11 Thread cdknight via FreeIPA-users
Thanks for the responses. Therefore, I will instead have to restrict access to the Web UI either by creating an HBAC rule (this is my understanding of what to do), and instead allowing them access a secondary self-service UI like https://github.com/ubccr/mokey. While this secondary software

[Freeipa-users] Re: How to prevent non-admin users of FreeIPA from reading the list of users in the web interface?

2018-12-11 Thread Alexander Bokovoy via FreeIPA-users
On ti, 11 joulu 2018, cdknight via FreeIPA-users wrote: When a user signs in to FreeIPA, I do not want them to be able to view the list of users in my LDAP server under the "Active users" link. I still want them to be able to administer self-service, so they can reset their password, add OTP

[Freeipa-users] Re: How to prevent non-admin users of FreeIPA from reading the list of users in the web interface?

2018-12-10 Thread Florence Blanc-Renaud via FreeIPA-users
On 12/11/18 1:36 AM, cdknight via FreeIPA-users wrote: When a user signs in to FreeIPA, I do not want them to be able to view the list of users in my LDAP server under the "Active users" link. I still want them to be able to administer self-service, so they can reset their password, add OTP