Re: [Freeipa-users] Permission not working as expected

2016-08-30 Thread Rob Crittenden
Alexander Bokovoy wrote: On Tue, 30 Aug 2016, Rob Crittenden wrote: Alexander Bokovoy wrote: On Tue, 30 Aug 2016, Rob Crittenden wrote: Alexander Bokovoy wrote: On Tue, 30 Aug 2016, Deepak Dimri wrote: Ok i got it now. Let me try this with role + privilege having three set of permissions 1)

Re: [Freeipa-users] Permission not working as expected

2016-08-30 Thread Alexander Bokovoy
On Tue, 30 Aug 2016, Rob Crittenden wrote: Alexander Bokovoy wrote: On Tue, 30 Aug 2016, Rob Crittenden wrote: Alexander Bokovoy wrote: On Tue, 30 Aug 2016, Deepak Dimri wrote: Ok i got it now. Let me try this with role + privilege having three set of permissions 1) memberOf hostgroup to mana

Re: [Freeipa-users] Permission not working as expected

2016-08-30 Thread Rob Crittenden
Alexander Bokovoy wrote: On Tue, 30 Aug 2016, Rob Crittenden wrote: Alexander Bokovoy wrote: On Tue, 30 Aug 2016, Deepak Dimri wrote: Ok i got it now. Let me try this with role + privilege having three set of permissions 1) memberOf hostgroup to manage the permissions to the hosts 2) permissio

Re: [Freeipa-users] Permission not working as expected

2016-08-30 Thread Alexander Bokovoy
On Tue, 30 Aug 2016, Rob Crittenden wrote: Alexander Bokovoy wrote: On Tue, 30 Aug 2016, Deepak Dimri wrote: Ok i got it now. Let me try this with role + privilege having three set of permissions 1) memberOf hostgroup to manage the permissions to the hosts 2) permission on cn=hostgroup to manag

Re: [Freeipa-users] Permission not working as expected

2016-08-30 Thread Rob Crittenden
ype (UTF-8-encoded string). userClass is used for auto membership. rob Best Regards,Deepak Date: Tue, 30 Aug 2016 18:36:21 +0300 From: aboko...@redhat.com To: deepak_di...@hotmail.com CC: freeipa-users@redhat.com Subject: Re: [Freeipa-users] Permission not working as expected On Tue, 30 Aug 2016

Re: [Freeipa-users] Permission not working as expected

2016-08-30 Thread Alexander Bokovoy
Regards,Deepak Date: Tue, 30 Aug 2016 18:36:21 +0300 From: aboko...@redhat.com To: deepak_di...@hotmail.com CC: freeipa-users@redhat.com Subject: Re: [Freeipa-users] Permission not working as expected On Tue, 30 Aug 2016, Deepak Dimri wrote: >Hi Alexander, > >Since i do not want myadmi

Re: [Freeipa-users] Permission not working as expected

2016-08-30 Thread Deepak Dimri
an member attribute other than AWS EC2 instance name... Best Regards,Deepak > Date: Tue, 30 Aug 2016 18:36:21 +0300 > From: aboko...@redhat.com > To: deepak_di...@hotmail.com > CC: freeipa-users@redhat.com > Subject: Re: [Freeipa-users] Permission not working as expected > >

Re: [Freeipa-users] Permission not working as expected

2016-08-30 Thread Alexander Bokovoy
work for you in AWS, though, so this is why I'm saying it is an organizational issue, not really a technical one. Thanks for your great support! regards,Deepak From: deepak_di...@hotmail.com To: aboko...@redhat.com CC: freeipa-users@redhat.com Subject: RE: [Freeipa-users] Permission n

Re: [Freeipa-users] Permission not working as expected

2016-08-30 Thread Deepak Dimri
o gets access to delete and manage other hosts outside of myhostgroup which i dont want! Thanks & Regards,Deepak > Date: Tue, 30 Aug 2016 16:10:00 +0300 > From: aboko...@redhat.com > To: deepak_di...@hotmail.com > CC: freeipa-users@redhat.com > Subject: Re: [Freeipa-users]

Re: [Freeipa-users] Permission not working as expected

2016-08-30 Thread Deepak Dimri
typo correction below! From: deepak_di...@hotmail.com To: aboko...@redhat.com CC: freeipa-users@redhat.com Subject: RE: [Freeipa-users] Permission not working as expected Date: Tue, 30 Aug 2016 09:04:36 -0400 Hi Alexander, i did try adding the "member" effective attribute in GUI and

Re: [Freeipa-users] Permission not working as expected

2016-08-30 Thread Alexander Bokovoy
On Tue, 30 Aug 2016, Deepak Dimri wrote: Hi Alexander, i did try adding the "member" effective attribute in GUI and also from the command prompt But the error is not going away when i try to delete the host from my taphostgroup. for me it only works if i have (&(cn=taphostgroup)(objectclass=ipaob

Re: [Freeipa-users] Permission not working as expected

2016-08-30 Thread Deepak Dimri
Date: Tue, 30 Aug 2016 13:27:59 +0300 > From: aboko...@redhat.com > To: deepak_di...@hotmail.com > CC: freeipa-users@redhat.com > Subject: Re: [Freeipa-users] Permission not working as expected > > On Tue, 30 Aug 2016, Deepak Dimri wrote: > >I did try the exact steps from t

Re: [Freeipa-users] Permission not working as expected

2016-08-30 Thread Alexander Bokovoy
On Tue, 30 Aug 2016, Deepak Dimri wrote: I did try the exact steps from the blog but alas still it did not work. getting same error :( I don't give rights to write to 'member' attribute in the blog. You have to adopt to your situation, obviously. -- / Alexander Bokovoy -- Manage your subscri

Re: [Freeipa-users] Permission not working as expected

2016-08-30 Thread Deepak Dimri
=accounts,dc=us-west-2,dc=compute,dc=amazonaws,dc=com'. Regards,Deepak > Date: Tue, 30 Aug 2016 13:04:07 +0300 > From: aboko...@redhat.com > To: deepak_di...@hotmail.com > CC: freeipa-users@redhat.com > Subject: Re: [Freeipa-users] Permission not working as expected >

Re: [Freeipa-users] Permission not working as expected

2016-08-30 Thread Alexander Bokovoy
On Tue, 30 Aug 2016, Deepak Dimri wrote: Hi Alexander, Thanks for the reply i tried exact steps below but it still not working. the admin user added to new role and privilege we have created is getting an error when trying to add or remove host of myhostgroup. ip-172-31-29-153.us-west-2.compute

Re: [Freeipa-users] Permission not working as expected

2016-08-30 Thread Deepak Dimri
CC: freeipa-users@redhat.com > Subject: Re: [Freeipa-users] Permission not working as expected > > On Tue, 30 Aug 2016, Alexander Bokovoy wrote: > >On Mon, 29 Aug 2016, Deepak Dimri wrote: > >>Hi All, > >>I have created below permission for my "testhostgroup" with

Re: [Freeipa-users] Permission not working as expected

2016-08-30 Thread Alexander Bokovoy
On Tue, 30 Aug 2016, Alexander Bokovoy wrote: On Tue, 30 Aug 2016, Alexander Bokovoy wrote: On Mon, 29 Aug 2016, Deepak Dimri wrote: Hi All, I have created below permission for my "testhostgroup" with the expectation that this permission will only allow write permission to the members of "testh

Re: [Freeipa-users] Permission not working as expected

2016-08-29 Thread Alexander Bokovoy
On Tue, 30 Aug 2016, Alexander Bokovoy wrote: On Mon, 29 Aug 2016, Deepak Dimri wrote: Hi All, I have created below permission for my "testhostgroup" with the expectation that this permission will only allow write permission to the members of "testhostgroup" but, then it allows me to add/delete

Re: [Freeipa-users] Permission not working as expected

2016-08-29 Thread Alexander Bokovoy
On Mon, 29 Aug 2016, Deepak Dimri wrote: Hi All, I have created below permission for my "testhostgroup" with the expectation that this permission will only allow write permission to the members of "testhostgroup" but, then it allows me to add/delete other hostgroup members as well. I tried changi

[Freeipa-users] Permission not working as expected

2016-08-29 Thread Deepak Dimri
Hi All, I have created below permission for my "testhostgroup" with the expectation that this permission will only allow write permission to the members of "testhostgroup" but, then it allows me to add/delete other hostgroup members as well. I tried changing the effective attribute to "memberof"