Thanks a lot! We will try to work it out.
-Original Message-
From: Martin Kosek [mailto:mko...@redhat.com]
Sent: Monday, November 11, 2013 12:52 PM
To: Исаев Виталий Анатольевич; Rob Crittenden; freeipa-users@redhat.com
Subject: Re: [Freeipa-users] Access differentiation in group policy
disallow the admin_group1 to add users or user groups from other isolated
> groups?
> ipa group-add-member --users=user_group2 group1
> // And now I can change user_group2's lastname.
> ipa user-mod user_group2 --last="Group 1"
>
> Thanks a lot.
>
> -
r-mod user_group2 --last="Group 1"
Thanks a lot.
-Original Message-----
From: Rob Crittenden [mailto:rcrit...@redhat.com]
Sent: Friday, November 08, 2013 8:48 PM
To: Исаев Виталий Анатольевич; freeipa-users@redhat.com
Subject: Re: [Freeipa-users] Access differentiation in group policy
redhat.com
Subject: Re: [Freeipa-users] Access differentiation in group policy
Исаев Виталий Анатольевич wrote:
Dear colleagues, we faced with an issue of access differentiation for
junior IPA admins. Our idea was to create several (say, three –
group1, group2, group3) isolated groups with one ju
rcrit...@redhat.com]
Sent: Friday, November 08, 2013 7:47 PM
To: Исаев Виталий Анатольевич; freeipa-users@redhat.com
Subject: Re: [Freeipa-users] Access differentiation in group policy
Исаев Виталий Анатольевич wrote:
> Dear colleagues, we faced with an issue of access differentiation for
>
Subject: Re: [Freeipa-users] Access differentiation in group policy
Исаев Виталий Анатольевич wrote:
> Dear colleagues, we faced with an issue of access differentiation for
> junior IPA admins. Our idea was to create several (say, three –
> group1, group2, group3) isolated groups with o
Исаев Виталий Анатольевич wrote:
Dear colleagues, we faced with an issue of access differentiation for
junior IPA admins. Our idea was to create several (say, three – group1,
group2, group3) isolated groups with one junior admin per group.
The group isolation means that admin of group1 is not ab
Dear colleagues, we faced with an issue of access differentiation for junior
IPA admins. Our idea was to create several (say, three - group1, group2,
group3) isolated groups with one junior admin per group.
The group isolation means that admin of group1 is not able to add to his group
neither u