summaryrefslogtreecommitdiffstats
path: root/src/providers/ipa
diff options
context:
space:
mode:
authorSumit Bose <sbose@redhat.com>2010-10-20 12:58:50 +0200
committerStephen Gallagher <sgallagh@redhat.com>2010-10-22 08:11:14 -0400
commit18a45c63a7902251a0d0b92f78f78eb7d26a0046 (patch)
tree05dc02a87f0aaa472790278b7a228a0494c0a621 /src/providers/ipa
parent59cc610d3a4885c5d37185b9adad39168feb6b55 (diff)
downloadsssd-18a45c63a7902251a0d0b92f78f78eb7d26a0046.tar.gz
sssd-18a45c63a7902251a0d0b92f78f78eb7d26a0046.tar.xz
sssd-18a45c63a7902251a0d0b92f78f78eb7d26a0046.zip
Download only enabled IPA HBAC rules
Diffstat (limited to 'src/providers/ipa')
-rw-r--r--src/providers/ipa/ipa_access.c4
1 files changed, 3 insertions, 1 deletions
diff --git a/src/providers/ipa/ipa_access.c b/src/providers/ipa/ipa_access.c
index 223bf1655..979959fb1 100644
--- a/src/providers/ipa/ipa_access.c
+++ b/src/providers/ipa/ipa_access.c
@@ -50,6 +50,7 @@
#define IPA_CN "cn"
#define IPA_MEMBER_SERVICE "memberService"
#define IPA_SERVICE_CATEGORY "serviceCategory"
+#define IPA_TRUE_VALUE "TRUE"
#define IPA_HOST_BASE_TMPL "cn=computers,cn=accounts,%s"
#define IPA_HBAC_BASE_TMPL "cn=hbac,%s"
@@ -1085,7 +1086,8 @@ static struct tevent_req *hbac_get_rules_send(TALLOC_CTX *memctx,
state->hbac_filter = talloc_asprintf(state,
"(&(objectclass=ipaHBACRule)"
- "(|(%s=%s)(%s=%s)",
+ "(%s=%s)(|(%s=%s)(%s=%s)",
+ IPA_ENABLED_FLAG, IPA_TRUE_VALUE,
IPA_HOST_CATEGORY, "all",
IPA_MEMBER_HOST, host_dn);
if (state->hbac_filter == NULL) {