diff options
Diffstat (limited to 'ipa-admintools/ipa-groupmod')
-rw-r--r-- | ipa-admintools/ipa-groupmod | 93 |
1 files changed, 76 insertions, 17 deletions
diff --git a/ipa-admintools/ipa-groupmod b/ipa-admintools/ipa-groupmod index 4d8dd4d5..c7e6e1fa 100644 --- a/ipa-admintools/ipa-groupmod +++ b/ipa-admintools/ipa-groupmod @@ -29,12 +29,16 @@ import ipa.ipaerror import xmlrpclib import kerberos import ldap +import errno def usage(): - print "ipa-groupmod [-a] [-r] user group" - print "ipa-groupmod [-d|--desc description STRING] group" + print "ipa-groupmod [-a|--add] [-r|--remove] user group" + print "ipa-groupmod [-d|--desc description STRING] [--addattr attribute=value] [--delattr attribute] [--setattr attribute=value] group" sys.exit(1) +def set_add_usage(which): + print "%s option usage: --%s NAME=VALUE" % (which, which) + def parse_options(): parser = OptionParser() parser.add_option("-a", "--add", dest="add", action="store_true", @@ -43,20 +47,38 @@ def parse_options(): help="Remove a user from the group") parser.add_option("-d", "--description", dest="desc", help="Modify the description of the group") + parser.add_option("--addattr", dest="addattr", + help="Adds an attribute or values to that attribute, attr=value", + action="append") + parser.add_option("--delattr", dest="delattr", + help="Remove an attribute", action="append") + parser.add_option("--setattr", dest="setattr", + help="Set an attribute, dropping any existing values that may exist", + action="append") parser.add_option("--usage", action="store_true", help="Program usage") args = ipa.config.init_config(sys.argv) options, args = parser.parse_args(args) - if (not options.add and not options.remove) and (not options.desc): + if (not options.add and not options.remove) and (not options.desc and + not options.addattr and not options.delattr and not options.setattr): usage() return options, args -def get_group(client, group_cn): +def get_group(client, options, group_cn): try: - group = client.get_entry_by_cn(group_cn) + attrs = ['*'] + + # in case any attributes being modified are operational such as + # nsaccountlock. Any attribute to be deleted needs to be included + # in the original record so it can be seen as being removed. + if options.delattr: + for d in options.delattr: + attrs.append(d) + group = client.get_entry_by_cn(group_cn, sattrs=attrs) + except ipa.ipaerror.IPAError, e: print "%s" % e.message return None @@ -69,32 +91,69 @@ def main(): if (options.add or options.remove) and (len(args) != 3): usage() - if (options.desc and (len(args) != 2)): + elif ((options.desc or options.addattr or options.delattr or options.setattr) and (len(args) != 2)): usage() try: client = ipaclient.IPAClient() if options.add: - group = get_group(client, args[2]) + group = get_group(client, options, args[2]) if group is None: return 1 - client.add_user_to_group(args[1], group.dn) - print args[1] + " successfully added to " + args[2] + users = args[1].split(',') + for user in users: + client.add_user_to_group(user, group.dn) + print user + " successfully added to " + args[2] elif options.remove: - group = get_group(client, args[2]) + group = get_group(client, options, args[2]) if group is None: return 1 - client.remove_user_from_group(args[1], group.dn) - print args[1] + " successfully removed" - elif options.desc: - group = get_group(client, args[1]) + users = args[1].split(',') + for user in users: + client.remove_user_from_group(user, group.dn) + print user + " successfully removed" + else: + group = get_group(client, options, args[1]) if group is None: return 1 - group.setValue('description', options.desc) + + if options.desc: + group.setValue('description', options.desc) + + if options.delattr: + for d in options.delattr: + group.delValue(d) + + if options.setattr: + for s in options.setattr: + s = s.split('=') + if len(s) != 2: + set_add_usage("set") + sys.exit(1) + (attr,value) = s + group.setValue(attr, value) + + if options.addattr: + for a in options.addattr: + a = a.split('=') + if len(a) != 2: + set_add_usage("add") + sys.exit(1) + (attr,value) = a + cvalue = group.getValue(attr) + if cvalue: + if isinstance(cvalue,str): + cvalue = [cvalue] + value = cvalue + [value] + group.setValue(attr, value) + client.update_group(group) print args[1] + " successfully updated" - except xmlrpclib.Fault, f: - print f.faultString + except xmlrpclib.Fault, fault: + if fault.faultCode == errno.ECONNREFUSED: + print "The IPA XML-RPC service is not responding." + else: + print fault.faultString return 1 except kerberos.GSSError, e: print "Could not initialize GSSAPI: %s/%s" % (e[0][0][0], e[0][1][0]) |