summaryrefslogtreecommitdiffstats
path: root/install
diff options
context:
space:
mode:
authorRob Crittenden <rcritten@redhat.com>2011-02-08 23:11:50 -0500
committerRob Crittenden <rcritten@redhat.com>2011-02-10 11:16:58 -0500
commitd9eb19b0e83222ae4a0f69f3adec6a1f80dbec38 (patch)
tree0eaa52a0bc187a706c0ed0cbec13361e455b947f /install
parent121da04579e4f3ce42fcead739cb75b460662bf7 (diff)
downloadfreeipa-d9eb19b0e83222ae4a0f69f3adec6a1f80dbec38.tar.gz
freeipa-d9eb19b0e83222ae4a0f69f3adec6a1f80dbec38.tar.xz
freeipa-d9eb19b0e83222ae4a0f69f3adec6a1f80dbec38.zip
Make main selfservice aci visible to the selfservice plugin.
ticket 934
Diffstat (limited to 'install')
-rw-r--r--install/share/default-aci.ldif4
1 files changed, 2 insertions, 2 deletions
diff --git a/install/share/default-aci.ldif b/install/share/default-aci.ldif
index 7c0ae8bd..88269d28 100644
--- a/install/share/default-aci.ldif
+++ b/install/share/default-aci.ldif
@@ -15,10 +15,10 @@ aci: (targetattr = "krbPrincipalName || krbCanonicalName || krbUPEnabled || krbM
aci: (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,$SUFFIX";)
aci: (targetattr = "*")(target = "ldap:///cn=*,ou=SUDOers,$SUFFIX")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)
-dn: cn=users,cn=accounts,$SUFFIX
+dn: $SUFFIX
changetype: modify
add: aci
-aci: (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeeType || businesscategory || ou")(version 3.0;acl "Self service";allow (write) userdn = "ldap:///self";)
+aci: (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)
dn: cn=etc,$SUFFIX
changetype: modify