summaryrefslogtreecommitdiffstats
path: root/install/share
diff options
context:
space:
mode:
authorJr Aquino <jr.aquino@citrix.com>2011-01-27 15:15:15 -0800
committerAdam Young <ayoung@redhat.com>2011-01-27 22:22:38 -0500
commit7b04b2240b92cc586fc06a8686c3616b020137fe (patch)
treef4e4dd5f140c5fde6a81ac65e9f8027e8c4f7fa3 /install/share
parent3cb33d74aecbd122e61cffd8226ea84389c15951 (diff)
downloadfreeipa-7b04b2240b92cc586fc06a8686c3616b020137fe.tar.gz
freeipa-7b04b2240b92cc586fc06a8686c3616b020137fe.tar.xz
freeipa-7b04b2240b92cc586fc06a8686c3616b020137fe.zip
block anonymous access to sudo info https://fedorahosted.org/freeipa/ticket/865
Diffstat (limited to 'install/share')
-rw-r--r--install/share/default-aci.ldif6
1 files changed, 6 insertions, 0 deletions
diff --git a/install/share/default-aci.ldif b/install/share/default-aci.ldif
index 8b00f4609..5a9d6e2fc 100644
--- a/install/share/default-aci.ldif
+++ b/install/share/default-aci.ldif
@@ -13,6 +13,7 @@ aci: (targetattr = "userPassword || krbPrincipalKey || krbPasswordExpiration ||
aci: (targetattr = "krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount")(version 3.0; acl "KDC System Account can update some fields"; allow (write) userdn="ldap:///uid=kdc,cn=sysaccounts,cn=etc,$SUFFIX";)
aci: (targetattr = "krbPrincipalName || krbCanonicalName || krbUPEnabled || krbMKey || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount")(version 3.0; acl "Only the KDC System Account has access to kerberos material"; allow (read, search, compare) userdn="ldap:///uid=kdc,cn=sysaccounts,cn=etc,$SUFFIX";)
aci: (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,$SUFFIX";)
+aci: (targetattr = "*")(target = "ldap:///cn=*,ou=SUDOers,$SUFFIX")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)
dn: cn=users,cn=accounts,$SUFFIX
changetype: modify
@@ -73,3 +74,8 @@ dn: cn=hbac,$SUFFIX
changetype: modify
add: aci
aci: (targetattr = "*")(version 3.0; acl "No anonymous access to hbac"; deny (read,search,compare) userdn != "ldap:///all";)
+
+dn: cn=sudo,$SUFFIX
+changetype: modify
+add: aci
+aci: (targetattr = "*")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)