summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorRob Crittenden <rcritten@redhat.com>2012-02-09 16:52:07 -0500
committerMartin Kosek <mkosek@redhat.com>2012-02-15 12:28:53 +0100
commit03de4df2aca256d8c417a05a32a953c0dc9d055a (patch)
treeead654df48d3e5bbddc9b6a411aca1de80d32960
parent578669daa42b1b34d5e76462aa42dea89d1a2f32 (diff)
downloadfreeipa.git-03de4df2aca256d8c417a05a32a953c0dc9d055a.tar.gz
freeipa.git-03de4df2aca256d8c417a05a32a953c0dc9d055a.tar.xz
freeipa.git-03de4df2aca256d8c417a05a32a953c0dc9d055a.zip
Add update files for SELinuxUserMap
https://fedorahosted.org/freeipa/ticket/2344
-rw-r--r--install/updates/10-selinuxusermap.update50
-rw-r--r--install/updates/50-ipaconfig.update4
-rw-r--r--install/updates/Makefile.am1
3 files changed, 53 insertions, 2 deletions
diff --git a/install/updates/10-selinuxusermap.update b/install/updates/10-selinuxusermap.update
new file mode 100644
index 00000000..431477ad
--- /dev/null
+++ b/install/updates/10-selinuxusermap.update
@@ -0,0 +1,50 @@
+# Add the SELinux User map config schema
+dn: cn=schema
+add:attributeTypes:
+ ( 2.16.840.1.113730.3.8.3.26
+ NAME 'ipaSELinuxUserMapDefault'
+ DESC 'Default SELinux user'
+ EQUALITY caseIgnoreMatch
+ ORDERING caseIgnoreMatch
+ SUBSTR caseIgnoreSubstringsMatch
+ SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE
+ X-ORIGIN 'IPA v3')
+add:attributeTypes:
+ ( 2.16.840.1.113730.3.8.3.27
+ NAME 'ipaSELinuxUserMapOrder'
+ DESC 'Available SELinux user context ordering'
+ EQUALITY caseIgnoreMatch
+ ORDERING caseIgnoreMatch
+ SUBSTR caseIgnoreSubstringsMatch
+ SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE
+ X-ORIGIN 'IPA v3')
+ X-ORIGIN 'IPA v3')
+replace:objectClasses:( 2.16.840.1.113730.3.8.2.1 NAME 'ipaGuiConfig' AUXILIARY MAY ( ipaUserSearchFields $$ ipaGroupSearchFields $$ ipaSearchTimeLimit $$ ipaSearchRecordsLimit $$ ipaCustomFields $$ ipaHomesRootDir $$ ipaDefaultLoginShell $$ ipaDefaultPrimaryGroup $$ ipaMaxUsernameLength $$ ipaPwdExpAdvNotify $$ ipaUserObjectClasses $$ ipaGroupObjectClasses $$ ipaDefaultEmailDomain $$ ipaMigrationEnabled $$ ipaCertificateSubjectBase ) )::( 2.16.840.1.113730.3.8.2.1 NAME 'ipaGuiConfig' AUXILIARY MAY ( ipaUserSearchFields $$ ipaGroupSearchFields $$ ipaSearchTimeLimit $$ ipaSearchRecordsLimit $$ ipaCustomFields $$ ipaHomesRootDir $$ ipaDefaultLoginShell $$ ipaDefaultPrimaryGroup $$ ipaMaxUsernameLength $$ ipaPwdExpAdvNotify $$ ipaUserObjectClasses $$ ipaGroupObjectClasses $$ ipaDefaultEmailDomain $$ ipaMigrationEnabled $$ ipaCertificateSubjectBase $$ ipaSELinuxUserMapDefault $$ ipaSELinuxUserMapOrder) )
+
+# Add the SELinux User map schema
+add:attributeTypes:
+ ( 2.16.840.1.113730.3.8.11.30
+ NAME 'ipaSELinuxUser'
+ DESC 'An SELinux user'
+ EQUALITY caseIgnoreMatch
+ ORDERING caseIgnoreOrderingMatch
+ SUBSTR caseIgnoreSubstringsMatch
+ SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 SINGLE-VALUE
+ X-ORIGIN 'IPA v3')
+add:objectClasses:
+ ( 2.16.840.1.113730.3.8.12.10
+ NAME 'ipaSELinuxUserMap' SUP ipaAssociation
+ STRUCTURAL MUST ipaSELinuxUser
+ MAY ( accessTime $$ seeAlso )
+
+# Create the SELinux User map container
+dn: cn=selinux,$SUFFIX
+default:objectClass: top
+default:objectClass: nsContainer
+default:cn: selinux
+
+dn: cn=usermap,cn=selinux,$SUFFIX
+default:objectClass: top
+default:objectClass: nsContainer
+default:cn: usermap
+
diff --git a/install/updates/50-ipaconfig.update b/install/updates/50-ipaconfig.update
index 40ce9335..b08df180 100644
--- a/install/updates/50-ipaconfig.update
+++ b/install/updates/50-ipaconfig.update
@@ -1,5 +1,5 @@
dn: cn=ipaConfig,cn=etc,$SUFFIX
-default:ipaSELinuxUserMapOrder: guest_u:s0$$xguest_u:s0$$user_u:s0-s0:c0.c1023$$staff_u:s0-s0:c0.c1023$$unconfined_u:s0-s0:c0.c1023
-default:ipaSELinuxUserMapDefault: guest_u:s0
+add:ipaSELinuxUserMapOrder: guest_u:s0$$xguest_u:s0$$user_u:s0-s0:c0.c1023$$staff_u:s0-s0:c0.c1023$$unconfined_u:s0-s0:c0.c1023
+add:ipaSELinuxUserMapDefault: guest_u:s0
add:ipaUserObjectClasses: ipasshuser
diff --git a/install/updates/Makefile.am b/install/updates/Makefile.am
index 89d5aa12..840e934b 100644
--- a/install/updates/Makefile.am
+++ b/install/updates/Makefile.am
@@ -6,6 +6,7 @@ app_DATA = \
10-RFC2307bis.update \
10-RFC4876.update \
10-config.update \
+ 10-selinuxusermap.update \
10-sudo.update \
10-ssh.update \
19-managed-entries.update \