diff options
author | Petr Viktorin <pviktori@redhat.com> | 2014-04-29 21:32:29 +0200 |
---|---|---|
committer | Petr Viktorin <pviktori@redhat.com> | 2014-05-26 12:12:35 +0200 |
commit | 63becae88c6c270b98f0432dc474b661b82f3119 (patch) | |
tree | 42215fed49d231ae59f51848279ec88b677419db /install/share/default-aci.ldif | |
parent | 993c1c8557aafb890199b1c443ebd2d895ae6ba6 (diff) | |
download | freeipa-63becae88c6c270b98f0432dc474b661b82f3119.tar.gz freeipa-63becae88c6c270b98f0432dc474b661b82f3119.tar.xz freeipa-63becae88c6c270b98f0432dc474b661b82f3119.zip |
Set user addressbook/IPA attribute read ACI to anonymous on upgrades from 3.x
When upgrading from an "old" IPA, or installing the first "new" replica,
we need to keep allowing anonymous access to many user attributes.
Add an optional 'fixup_function' to the managed permission templates,
and use it to set the bind rule type to 'anonymous' when installing
(or upgrading to) the first "new" master.
This assumes that the anonymous read ACI will be removed in a "new" IPA.
Part of the work for: https://fedorahosted.org/freeipa/ticket/3566
Reviewed-By: Martin Kosek <mkosek@redhat.com>
Diffstat (limited to 'install/share/default-aci.ldif')
0 files changed, 0 insertions, 0 deletions