summaryrefslogtreecommitdiffstats
path: root/install/updates/20-aci.update
diff options
context:
space:
mode:
authorRob Crittenden <rcritten@redhat.com>2011-02-17 17:19:24 -0500
committerRob Crittenden <rcritten@redhat.com>2011-02-18 15:29:51 -0500
commit496ab3f738d55e9356142048dcfef2caa46c121f (patch)
tree988cfc48e76564cc16fbb8935f46a97ed71f4d9b /install/updates/20-aci.update
parent6943acc1615da141d86dc9a84c7f86629199516f (diff)
downloadfreeipa-496ab3f738d55e9356142048dcfef2caa46c121f.tar.gz
freeipa-496ab3f738d55e9356142048dcfef2caa46c121f.tar.xz
freeipa-496ab3f738d55e9356142048dcfef2caa46c121f.zip
Add aci to make managed netgroups immutable.
ticket 962
Diffstat (limited to 'install/updates/20-aci.update')
-rw-r--r--install/updates/20-aci.update4
1 files changed, 4 insertions, 0 deletions
diff --git a/install/updates/20-aci.update b/install/updates/20-aci.update
new file mode 100644
index 000000000..42f1e9fe6
--- /dev/null
+++ b/install/updates/20-aci.update
@@ -0,0 +1,4 @@
+# Don't allow managed netgroups to be modified
+dn: cn=ng,cn=alt,$SUFFIX
+add:aci: '(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)'
+