|
|
e3ffab |
From 8e4181b467d4135dccb23400f8afad6141f44b3a Mon Sep 17 00:00:00 2001
|
|
|
e3ffab |
From: Alexander Bokovoy <abokovoy@redhat.com>
|
|
|
e3ffab |
Date: Fri, 24 Oct 2014 15:01:27 +0300
|
|
|
e3ffab |
Subject: [PATCH] Add ipaSshPubkey and gidNumber to the ACI to read ID user
|
|
|
e3ffab |
overrides
|
|
|
e3ffab |
|
|
|
e3ffab |
https://fedorahosted.org/freeipa/ticket/4664
|
|
|
e3ffab |
|
|
|
e3ffab |
Reviewed-By: Martin Kosek <mkosek@redhat.com>
|
|
|
e3ffab |
---
|
|
|
e3ffab |
ACI.txt | 2 +-
|
|
|
e3ffab |
ipalib/plugins/idviews.py | 1 +
|
|
|
e3ffab |
2 files changed, 2 insertions(+), 1 deletion(-)
|
|
|
e3ffab |
|
|
|
e3ffab |
diff --git a/ACI.txt b/ACI.txt
|
|
|
e3ffab |
index 27a5d2f3458ab313437060a9daea470a8f4e5203..6680f658ee1aa0f961b2681f700557ce6b9238f8 100644
|
|
|
e3ffab |
--- a/ACI.txt
|
|
|
e3ffab |
+++ b/ACI.txt
|
|
|
e3ffab |
@@ -131,7 +131,7 @@ aci: (targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:S
|
|
|
e3ffab |
dn: cn=views,cn=accounts,dc=ipa,dc=example
|
|
|
e3ffab |
aci: (targetattr = "cn || createtimestamp || description || entryusn || gidnumber || ipaanchoruuid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaGroupOverride)")(version 3.0;acl "permission:System: Read Group ID Overrides";allow (compare,read,search) userdn = "ldap:///all";)
|
|
|
e3ffab |
dn: cn=views,cn=accounts,dc=ipa,dc=example
|
|
|
e3ffab |
-aci: (targetattr = "createtimestamp || description || entryusn || gecos || homedirectory || ipaanchoruuid || ipaoriginaluid || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaUserOverride)")(version 3.0;acl "permission:System: Read User ID Overrides";allow (compare,read,search) userdn = "ldap:///all";)
|
|
|
e3ffab |
+aci: (targetattr = "createtimestamp || description || entryusn || gecos || gidnumber || homedirectory || ipaanchoruuid || ipaoriginaluid || ipasshpubkey || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaUserOverride)")(version 3.0;acl "permission:System: Read User ID Overrides";allow (compare,read,search) userdn = "ldap:///all";)
|
|
|
e3ffab |
dn: cn=ranges,cn=etc,dc=ipa,dc=example
|
|
|
e3ffab |
aci: (targetattr = "cn || createtimestamp || entryusn || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";)
|
|
|
e3ffab |
dn: cn=views,cn=accounts,dc=ipa,dc=example
|
|
|
e3ffab |
diff --git a/ipalib/plugins/idviews.py b/ipalib/plugins/idviews.py
|
|
|
e3ffab |
index bfa8675fb84a1d1e13f44b31e9384c9c783f4c4e..9c8721018325f56e681f168b55c31055bfd07345 100644
|
|
|
e3ffab |
--- a/ipalib/plugins/idviews.py
|
|
|
e3ffab |
+++ b/ipalib/plugins/idviews.py
|
|
|
e3ffab |
@@ -659,6 +659,7 @@ class idoverrideuser(baseidoverride):
|
|
|
e3ffab |
'ipapermdefaultattr': {
|
|
|
e3ffab |
'objectClass', 'ipaAnchorUUID', 'uidNumber', 'description',
|
|
|
e3ffab |
'homeDirectory', 'uid', 'ipaOriginalUid', 'loginShell', 'gecos',
|
|
|
e3ffab |
+ 'gidNumber', 'ipaSshPubkey',
|
|
|
e3ffab |
},
|
|
|
e3ffab |
},
|
|
|
e3ffab |
}
|
|
|
e3ffab |
--
|
|
|
e3ffab |
2.1.0
|
|
|
e3ffab |
|