diff options
author | Ana Krivokapic <akrivoka@redhat.com> | 2013-09-19 14:10:32 +0200 |
---|---|---|
committer | Martin Kosek <mkosek@redhat.com> | 2013-11-15 12:46:06 +0100 |
commit | dfea5989f7edeb9ebc2d4fe42641e8818222761a (patch) | |
tree | a755782e5a20f00e8bcb9d9a710bfcd47110f21a /install/updates | |
parent | d97386de5b68c90c53362dda54b126fdc97e00b6 (diff) | |
download | freeipa-dfea5989f7edeb9ebc2d4fe42641e8818222761a.tar.gz freeipa-dfea5989f7edeb9ebc2d4fe42641e8818222761a.tar.xz freeipa-dfea5989f7edeb9ebc2d4fe42641e8818222761a.zip |
Add a privilege and a permission needed for automember rebuild command
Design: http://www.freeipa.org/page/V3/Automember_rebuild_membership
https://fedorahosted.org/freeipa/ticket/3752
Diffstat (limited to 'install/updates')
-rw-r--r-- | install/updates/40-delegation.update | 19 |
1 files changed, 19 insertions, 0 deletions
diff --git a/install/updates/40-delegation.update b/install/updates/40-delegation.update index 64a6432ac..3fabdf9c7 100644 --- a/install/updates/40-delegation.update +++ b/install/updates/40-delegation.update @@ -373,3 +373,22 @@ add: member: 'cn=Host Administrators,cn=privileges,cn=pbac,$SUFFIX' dn: cn=Revoke Certificate,cn=permissions,cn=pbac,$SUFFIX add: member: 'cn=Host Administrators,cn=privileges,cn=pbac,$SUFFIX' + +# Automember tasks +dn: cn=Automember Task Administrator,cn=privileges,cn=pbac,$SUFFIX +default:objectClass: nestedgroup +default:objectClass: groupofnames +default:objectClass: top +default:cn: Automember Task Administrator +default:description: Automember Task Administrator + +dn: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,$SUFFIX +default:objectClass: groupofnames +default:objectClass: ipapermission +default:objectClass: top +default:cn: Add Automember Rebuild Membership Task +default:member: cn=Automember Task Administrator,cn=privileges,cn=pbac,$SUFFIX +default:ipapermissiontype: SYSTEM + +dn: cn=config +add:aci: '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,$SUFFIX";)' |