Re: [Freeipa-users] Delegation + visibility on users/user groups

2017-02-15 Thread Alexander Bokovoy
On ke, 15 helmi 2017, Michael Ströder wrote: On 2017-02-15 11:51, Alexander Bokovoy wrote: On ke, 15 helmi 2017, Gerald Zabos wrote: Use case: external customer gets limited access and MUST NOT see our internal users and/or other external customers. Not seeing other users or objects is no pos

Re: [Freeipa-users] Delegation + visibility on users/user groups

2017-02-15 Thread Michael Ströder
On 2017-02-15 11:51, Alexander Bokovoy wrote: On ke, 15 helmi 2017, Gerald Zabos wrote: Use case: external customer gets limited access and MUST NOT see our internal users and/or other external customers. Not seeing other users or objects is no possible with FreeIPA design. It is also securi

Re: [Freeipa-users] Delegation + visibility on users/user groups

2017-02-15 Thread Gerald Zabos
Hello Alexander, > Not seeing other users or objects is no possible with FreeIPA design. It is > also security through obscurity and doesn't really contribute anything. > You should be looking at proper permissions/roles to confine what bob and > others could actually do, not see. > I have pra

Re: [Freeipa-users] Delegation + visibility on users/user groups

2017-02-15 Thread Alexander Bokovoy
On ke, 15 helmi 2017, Gerald Zabos wrote: Hello all, after setting up a productive IPA 4.4 environment with eight nodes (master + replicas) on four different locations everything works well. Good job, guys. I am tinkering around with user management and prepared an example setup: - create one