# IPA generated ldif for pam_selinux roles. DO NOT EDIT # role: dn: ou= ,ou=pam_selinux_roles,xx=some,xx=ldap,xx=path - changetype: modify replace: service service: dn: ou= ,ou= ,ou=pam_selinux_roles,xx=some,xx=ldap,xx=path changetype: modify replace: selinux_user selinux_user: - changetype: modify replace: mls mls: dn: ou= ,ou= ,ou=PolicyKitRoles,xx=some,xx=ldap,xx=path changetype: modify replace: allow_any allow_any: - changetype: modify replace: allow_inactive allow_inactive: - changetype: modify replace: allow_active allow_active: