From 61eeea9e69483d5afbdefebcf068dac06749313f Mon Sep 17 00:00:00 2001 From: Petr Viktorin Date: Mon, 23 Jun 2014 13:37:33 +0200 Subject: netgroup: Add objectclass attribute to read permissions The entries were unreadable without this. Additional fix for: https://fedorahosted.org/freeipa/ticket/3566 Reviewed-By: Martin Kosek --- ACI.txt | 4 ++-- ipalib/plugins/netgroup.py | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/ACI.txt b/ACI.txt index 11af74a3d..d9eac3db0 100644 --- a/ACI.txt +++ b/ACI.txt @@ -71,9 +71,9 @@ aci: (targetattr = "krbdefaultencsalttypes || krbmaxrenewableage || krbmaxticket dn: cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=example aci: (targetattr = "krbmaxrenewableage || krbmaxticketlife")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read User Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=example";) dn: cn=System: Read Netgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=example -aci: (targetattr = "externalhost || member || memberhost || memberof || memberuser")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";) +aci: (targetattr = "externalhost || member || memberhost || memberof || memberuser || objectclass")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";) dn: cn=System: Read Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=example -aci: (targetattr = "cn || description || hostcategory || ipaenabledflag || ipauniqueid || nisdomainname || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";) +aci: (targetattr = "cn || description || hostcategory || ipaenabledflag || ipauniqueid || nisdomainname || objectclass || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";) dn: cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=example aci: (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=example";) dn: cn=System: Read Permissions,cn=permissions,cn=pbac,dc=ipa,dc=example diff --git a/ipalib/plugins/netgroup.py b/ipalib/plugins/netgroup.py index 8603f4cea..06fbc20f9 100644 --- a/ipalib/plugins/netgroup.py +++ b/ipalib/plugins/netgroup.py @@ -115,7 +115,7 @@ class netgroup(LDAPObject): 'ipapermright': {'read', 'search', 'compare'}, 'ipapermdefaultattr': { 'cn', 'description', 'hostcategory', 'ipaenabledflag', - 'ipauniqueid', 'nisdomainname', 'usercategory' + 'ipauniqueid', 'nisdomainname', 'usercategory', 'objectclass', }, }, 'System: Read Netgroup Membership': { @@ -124,7 +124,7 @@ class netgroup(LDAPObject): 'ipapermright': {'read', 'search', 'compare'}, 'ipapermdefaultattr': { 'externalhost', 'member', 'memberof', 'memberuser', - 'memberhost', + 'memberhost', 'objectclass', }, }, } -- cgit