summaryrefslogtreecommitdiffstats
path: root/install/updates
diff options
context:
space:
mode:
authorPetr Viktorin <pviktori@redhat.com>2014-06-19 13:01:06 +0200
committerMartin Kosek <mkosek@redhat.com>2014-06-19 17:13:03 +0200
commit18744d1833452600b93da0156a112f4e8c0013b0 (patch)
tree4d6ee5e2dd4a2cd34c28686b0ccf38fa9c91ada1 /install/updates
parentb243da415ecb2c28b5aa9bc563595efe35a40987 (diff)
downloadfreeipa-18744d1833452600b93da0156a112f4e8c0013b0.tar.gz
freeipa-18744d1833452600b93da0156a112f4e8c0013b0.tar.xz
freeipa-18744d1833452600b93da0156a112f4e8c0013b0.zip
Fix: Allow read access to masters, but not their services, to auth'd users
Fixes commit b243da415ecb2c28b5aa9bc563595efe35a40987 A bad version of the patch was sent and pushed. Part of the work for: https://fedorahosted.org/freeipa/ticket/3566 Reviewed-By: Martin Kosek <mkosek@redhat.com>
Diffstat (limited to 'install/updates')
-rw-r--r--install/updates/20-aci.update2
1 files changed, 1 insertions, 1 deletions
diff --git a/install/updates/20-aci.update b/install/updates/20-aci.update
index a10eb4077..42fca71f3 100644
--- a/install/updates/20-aci.update
+++ b/install/updates/20-aci.update
@@ -30,7 +30,7 @@ add:aci:'(targetfilter="(objectclass=nsContainer)")(version 3.0; acl "Deny read
# Read access to masters (but not their services)
dn: cn=masters,cn=ipa,cn=etc,$SUFFIX
-add:aci:'(targetfilter="(objectclass=nsContainer)")(target!="ldap:///cn=*,cn=*,cn=masters,cn=ipa,cn=etc,$SUFFIX")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'
+add:aci:'(targetfilter="(&(objectclass=nsContainer)(!(objectclass=ipaConfigObject)))")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'
# Read access to Kerberos container (cn=kerberos) and realm containers (cn=$REALM,cn=kerberos)
dn: cn=kerberos,$SUFFIX