pgreco / rpms / ipa

Forked from forks/areguera/rpms/ipa 4 years ago
Clone

Blame SOURCES/0106-Add-anonymous-read-ACI-for-DUA-profile.patch

e3ffab
From 113834837e775bfa40604d131725e9b34248465c Mon Sep 17 00:00:00 2001
e3ffab
From: Martin Kosek <mkosek@redhat.com>
e3ffab
Date: Tue, 20 Jan 2015 17:57:07 +0100
e3ffab
Subject: [PATCH] Add anonymous read ACI for DUA profile
e3ffab
e3ffab
DUA profile(s) are consumed by Solaris clients.
e3ffab
e3ffab
https://fedorahosted.org/freeipa/ticket/4850
e3ffab
e3ffab
Reviewed-By: Jan Cholasta <jcholast@redhat.com>
e3ffab
---
e3ffab
 ACI.txt                                              |  2 ++
e3ffab
 .../install/plugins/update_managed_permissions.py    | 20 ++++++++++++++++++++
e3ffab
 2 files changed, 22 insertions(+)
e3ffab
e3ffab
diff --git a/ACI.txt b/ACI.txt
e3ffab
index fe45d063e7d48c487e380ca3568b0f9368762c6d..67d583fabc295deb8aa5aab329bce5100c1b9088 100644
e3ffab
--- a/ACI.txt
e3ffab
+++ b/ACI.txt
e3ffab
@@ -298,6 +298,8 @@ dn: cn=certificates,cn=ipa,cn=etc,dc=ipa,dc=example
e3ffab
 aci: (targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";)
e3ffab
 dn: cn=dna,cn=ipa,cn=etc,dc=ipa,dc=example
e3ffab
 aci: (targetattr = "cn || createtimestamp || dnahostname || dnaportnum || dnaremainingvalues || dnaremotebindmethod || dnaremoteconnprotocol || dnasecureportnum || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=dnasharedconfig)")(version 3.0;acl "permission:System: Read DNA Configuration";allow (compare,read,search) userdn = "ldap:///all";)
e3ffab
+dn: ou=profile,dc=ipa,dc=example
e3ffab
+aci: (targetattr = "attributemap || authenticationmethod || bindtimelimit || cn || createtimestamp || credentiallevel || defaultsearchbase || defaultsearchscope || defaultserverlist || dereferencealiases || entryusn || followreferrals || modifytimestamp || objectclass || objectclassmap || ou || preferredserverlist || profilettl || searchtimelimit || serviceauthenticationmethod || servicecredentiallevel || servicesearchdescriptor")(targetfilter = "(|(objectclass=organizationalUnit)(objectclass=DUAConfigProfile))")(version 3.0;acl "permission:System: Read DUA Profile";allow (compare,read,search) userdn = "ldap:///anyone";)
e3ffab
 dn: cn=masters,cn=ipa,cn=etc,dc=ipa,dc=example
e3ffab
 aci: (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=example";)
e3ffab
 dn: cn=config
e3ffab
diff --git a/ipaserver/install/plugins/update_managed_permissions.py b/ipaserver/install/plugins/update_managed_permissions.py
e3ffab
index 032485aac5b84b12b91464f16870c9940b18bc2d..430a2919a315bfd8d8e6174a915890d44b782c5c 100644
e3ffab
--- a/ipaserver/install/plugins/update_managed_permissions.py
e3ffab
+++ b/ipaserver/install/plugins/update_managed_permissions.py
e3ffab
@@ -320,6 +320,26 @@ NONOBJECT_PERMISSIONS = {
e3ffab
             'winsyncsubtreepair',
e3ffab
         },
e3ffab
         'default_privileges': {'Replication Administrators'},
e3ffab
+    },
e3ffab
+    'System: Read DUA Profile': {
e3ffab
+        'ipapermlocation': DN('ou=profile', api.env.basedn),
e3ffab
+        'ipapermtargetfilter': {
e3ffab
+            '(|'
e3ffab
+                '(objectclass=organizationalUnit)'
e3ffab
+                '(objectclass=DUAConfigProfile)'
e3ffab
+            ')'
e3ffab
+        },
e3ffab
+        'ipapermbindruletype': 'anonymous',
e3ffab
+        'ipapermright': {'read', 'search', 'compare'},
e3ffab
+        'ipapermdefaultattr': {
e3ffab
+            'objectclass', 'ou', 'cn', 'defaultServerList',
e3ffab
+            'preferredServerList', 'defaultSearchBase', 'defaultSearchScope',
e3ffab
+            'searchTimeLimit', 'bindTimeLimit', 'credentialLevel',
e3ffab
+            'authenticationMethod', 'followReferrals', 'dereferenceAliases',
e3ffab
+            'serviceSearchDescriptor', 'serviceCredentialLevel',
e3ffab
+            'serviceAuthenticationMethod', 'objectclassMap', 'attributeMap',
e3ffab
+            'profileTTL'
e3ffab
+        },
e3ffab
     }
e3ffab
 }
e3ffab
 
e3ffab
-- 
e3ffab
2.1.0
e3ffab