summaryrefslogtreecommitdiffstats
path: root/src/config/etc/sssd.api.d/sssd-ipa.conf
diff options
context:
space:
mode:
authorStephen Gallagher <sgallagh@redhat.com>2011-07-01 16:12:58 -0400
committerStephen Gallagher <sgallagh@redhat.com>2011-08-01 12:18:33 -0400
commita2b1e0b4bce8281d7214329d6bc261cb8ca02784 (patch)
tree752d006411cbcee27bbc5215a8baef98ba0a4207 /src/config/etc/sssd.api.d/sssd-ipa.conf
parentfba08ceb9fb8a71f0a86dfcf8902b09a84a70211 (diff)
downloadsssd-a2b1e0b4bce8281d7214329d6bc261cb8ca02784.tar.gz
sssd-a2b1e0b4bce8281d7214329d6bc261cb8ca02784.tar.xz
sssd-a2b1e0b4bce8281d7214329d6bc261cb8ca02784.zip
Add ipa_hbac_treat_deny_as option
By default, we will treat the presence of any DENY rule as denying all users. This option will allow the admin to explicitly ignore DENY rules during a transitional period.
Diffstat (limited to 'src/config/etc/sssd.api.d/sssd-ipa.conf')
-rw-r--r--src/config/etc/sssd.api.d/sssd-ipa.conf1
1 files changed, 1 insertions, 0 deletions
diff --git a/src/config/etc/sssd.api.d/sssd-ipa.conf b/src/config/etc/sssd.api.d/sssd-ipa.conf
index c1adc878e..d7992b608 100644
--- a/src/config/etc/sssd.api.d/sssd-ipa.conf
+++ b/src/config/etc/sssd.api.d/sssd-ipa.conf
@@ -101,6 +101,7 @@ krb5_use_fast = str, None, false
[provider/ipa/access]
ipa_hbac_refresh = int, None, false
+ipa_hbac_treat_deny_as = str, None, false
[provider/ipa/chpass]