summaryrefslogtreecommitdiffstats
path: root/ACI.txt
diff options
context:
space:
mode:
authorTomas Babej <tbabej@redhat.com>2014-09-05 12:39:28 +0200
committerTomas Babej <tbabej@redhat.com>2014-09-17 14:41:51 +0200
commit8fb00a9d445c6af2a7fa189d4dd1d0ca4dde6d03 (patch)
tree3404c0c71f7f2215abff27da86c618e2548ab1fa /ACI.txt
parent843031f016c7dfa791c010d080fd8c607e13ad8f (diff)
downloadfreeipa-8fb00a9d445c6af2a7fa189d4dd1d0ca4dde6d03.tar.gz
freeipa-8fb00a9d445c6af2a7fa189d4dd1d0ca4dde6d03.tar.xz
freeipa-8fb00a9d445c6af2a7fa189d4dd1d0ca4dde6d03.zip
idviews: Split the idoverride commands into iduseroverride and idgroupoverride
Diffstat (limited to 'ACI.txt')
-rw-r--r--ACI.txt4
1 files changed, 3 insertions, 1 deletions
diff --git a/ACI.txt b/ACI.txt
index eb88d31a8..30ca95a09 100644
--- a/ACI.txt
+++ b/ACI.txt
@@ -119,7 +119,9 @@ aci: (targetattr = "businesscategory || cn || createtimestamp || description ||
dn: cn=hostgroups,cn=accounts,dc=ipa,dc=example
aci: (targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Remove Hostgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=example";)
dn: cn=views,cn=accounts,dc=ipa,dc=example
-aci: (targetattr = "cn || createtimestamp || description || entryusn || gidnumber || homedirectory || ipaanchoruuid || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaOverrideAnchor)")(version 3.0;acl "permission:System: Read ID Overrides";allow (compare,read,search) userdn = "ldap:///all";)
+aci: (targetattr = "cn || createtimestamp || description || entryusn || gidnumber || ipaanchoruuid || modifytimestamp || objectclass")(targetfilter = "(|(objectclass=ipaGroupOverride)(objectclass=ipaOverrideAnchor))")(version 3.0;acl "permission:System: Read Group ID Overrides";allow (compare,read,search) userdn = "ldap:///all";)
+dn: cn=views,cn=accounts,dc=ipa,dc=example
+aci: (targetattr = "createtimestamp || description || entryusn || homedirectory || ipaanchoruuid || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(|(objectclass=ipaOverrideAnchor)(objectclass=ipaUserOverride))")(version 3.0;acl "permission:System: Read User ID Overrides";allow (compare,read,search) userdn = "ldap:///all";)
dn: cn=ranges,cn=etc,dc=ipa,dc=example
aci: (targetattr = "cn || createtimestamp || entryusn || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";)
dn: cn=views,cn=accounts,dc=ipa,dc=example