From 66418c376763ea6eaeccf4215326f3d2ab1ee160 Mon Sep 17 00:00:00 2001 From: Pavel Reichl Date: Tue, 13 Jan 2015 17:43:30 -0500 Subject: GPO: add systemd-user to gpo default permit list Resolves: https://fedorahosted.org/sssd/ticket/2556 Reviewed-by: Stephen Gallagher (cherry picked from commit b49c6abe12721ee8442be1c1bd6c15443b518ca2) --- src/providers/ad/ad_gpo.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) (limited to 'src/providers/ad/ad_gpo.c') diff --git a/src/providers/ad/ad_gpo.c b/src/providers/ad/ad_gpo.c index 375ef1d8a..c45b7963e 100644 --- a/src/providers/ad/ad_gpo.c +++ b/src/providers/ad/ad_gpo.c @@ -187,6 +187,7 @@ int ad_gpo_process_cse_recv(struct tevent_req *req); #define GPO_CROND "crond" #define GPO_SUDO "sudo" #define GPO_SUDO_I "sudo-i" +#define GPO_SYSTEMD_USER "systemd-user" struct gpo_map_option_entry { enum gpo_map_type gpo_map_type; @@ -203,7 +204,8 @@ const char *gpo_map_remote_interactive_defaults[] = {GPO_SSHD, NULL}; const char *gpo_map_network_defaults[] = {GPO_FTP, GPO_SAMBA, NULL}; const char *gpo_map_batch_defaults[] = {GPO_CROND, NULL}; const char *gpo_map_service_defaults[] = {NULL}; -const char *gpo_map_permit_defaults[] = {GPO_SUDO, GPO_SUDO_I, NULL}; +const char *gpo_map_permit_defaults[] = {GPO_SUDO, GPO_SUDO_I, + GPO_SYSTEMD_USER, NULL}; const char *gpo_map_deny_defaults[] = {NULL}; struct gpo_map_option_entry gpo_map_option_entries[] = { -- cgit