summaryrefslogtreecommitdiffstats
path: root/install/updates/40-delegation.update
Commit message (Expand)AuthorAgeFilesLines
* Add permissions for certificate store.Jan Cholasta2014-07-301-0/+3
* Allow IPA master hosts to read and update IPA master information.Jan Cholasta2014-07-301-0/+4
* Allow IPA master hosts to update CA certificate in LDAP.Jan Cholasta2014-07-301-0/+2
* Convert Sudo Command Group default permissions to managedPetr Viktorin2014-06-241-27/+0
* Convert Sudo Command default permissions to managedPetr Viktorin2014-06-241-27/+0
* Convert SELinux User Map default permissions to managedPetr Viktorin2014-06-241-30/+0
* Convert HBAC Service Group default permissions to managedPetr Viktorin2014-06-241-26/+0
* Convert HBAC Service default permissions to managedPetr Viktorin2014-06-241-16/+0
* Convert HBAC Rule default permissions to managedPetr Viktorin2014-06-241-32/+0
* Convert Group default permissions to managedPetr Viktorin2014-06-241-5/+0
* Convert Automount default permissions to managedPetr Viktorin2014-06-241-21/+0
* Support requests with SAN in cert-request.Jan Cholasta2014-06-241-0/+15
* Convert Host default permissions to managedPetr Viktorin2014-06-231-28/+1
* Allow anonymous read access to virtual operation entriesPetr Viktorin2014-06-201-6/+0
* Convert Password Policy default permissions to managedPetr Viktorin2014-06-181-26/+0
* Convert COSTemplate default permissions to managedPetr Viktorin2014-06-181-24/+0
* Convert DNS default permissions to managedPetr Viktorin2014-06-181-3/+3
* Convert User default permissions to managedPetr Viktorin2014-06-101-16/+0
* Convert Sudo rule default permissions to managedPetr Viktorin2014-06-041-25/+0
* Add several managed read permissions under cn=etcPetr Viktorin2014-04-241-0/+7
* Add a new ipaVirtualOperation objectClass to virtual operationsPetr Viktorin2014-04-241-0/+39
* Add managed read permissions to automemberPetr Viktorin2014-04-171-0/+7
* Add managed read permissions to krbtpolicyPetr Viktorin2014-04-161-0/+7
* Add managed read permissions to pwpolicy and cosentryPetr Viktorin2014-04-141-0/+7
* Add managed read permissions to RBAC objectsPetr Viktorin2014-04-111-0/+9
* Add a privilege and a permission needed for automember rebuild commandAna Krivokapic2013-11-151-0/+19
* Add missing permissions to Host Administrators privilegeAna Krivokapic2013-04-241-0/+8
* Update sudocmd ACIs to use targetfilterPetr Viktorin2013-02-201-3/+8
* Use certmonger to renew CA subsystem certificatesRob Crittenden2012-07-301-0/+4
* Add automount map/key update permissionsMartin Kosek2012-07-101-0/+21
* Don't allow "Modify Group membership" permission to manage adminsRob Crittenden2012-02-231-0/+4
* Limit the change password permission so it can't change admin passwordsRob Crittenden2012-02-201-0/+5
* Add LDAP ACIs for SSH public key schema.Jan Cholasta2012-02-131-0/+21
* Add SELinux user mapping framework.Rob Crittenden2011-12-091-0/+38
* Reorder privileges so that memberof for permissions are generated properly.Rob Crittenden2011-12-081-21/+20
* Fix DNS permissions and membership in privilegesRob Crittenden2011-10-091-0/+6
* Disallow direct modifications to enrolledBy.Rob Crittenden2011-07-141-0/+4
* Allow a client to enroll using principal when the host has a OTPRob Crittenden2011-03-301-0/+18
* Use Sudo rather than SUDO as a label.Rob Crittenden2011-03-011-39/+39
* Add default roles and permissions for HBAC, SUDO and pw policyRob Crittenden2011-02-221-0/+224
* Add permission/privilege for updating IPA configuration.Rob Crittenden2011-02-141-0/+18
* Re-implement access control using an updated model.Rob Crittenden2010-12-011-732/+0
* Reduce the number of attributes a host is allowed to write.Rob Crittenden2010-11-301-2/+2
* Remove hardcoded domain value and replace with $SUFFIXRob Crittenden2010-11-041-3/+3
* Use correct attribute name, nshostlocation, not location.Rob Crittenden2010-11-031-1/+1
* Use correct description in hostgroup acis.Rob Crittenden2010-10-061-3/+3
* Remove reliance on the name 'admin' as a special user.Rob Crittenden2010-10-011-1/+1
* Allow decoupling of user-private groups.Rob Crittenden2010-08-101-8/+8
* Add container and initial ACIs for entitlement supportRob Crittenden2010-07-291-0/+37
* Add separate role group for enrolling hosts, enrollhostRob Crittenden2010-06-221-0/+8