summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorFraser Tweedale <ftweedal@redhat.com>2015-08-07 03:21:43 -0400
committerMartin Basti <mbasti@redhat.com>2015-08-11 17:26:24 +0200
commit9bbc798741c2872eaa6cc29d92c8b90104d65ee8 (patch)
tree3ae50ec313c8e674bc27e136f6ed6db04d0d71ad
parent1fc21e980bb901bf71f7ee024cdbb15c1caec3a7 (diff)
downloadfreeipa-9bbc798741c2872eaa6cc29d92c8b90104d65ee8.tar.gz
freeipa-9bbc798741c2872eaa6cc29d92c8b90104d65ee8.tar.xz
freeipa-9bbc798741c2872eaa6cc29d92c8b90104d65ee8.zip
Fix default CA ACL added during upgrade
The upgrade script is adding the default CA ACL with incorrect attributes - usercategory=all instead of servicecategory=all. Fix it to create the correct object. Fixes: https://fedorahosted.org/freeipa/ticket/5185 Reviewed-By: Martin Babinsky <mbabinsk@redhat.com>
-rw-r--r--ipaserver/install/server/upgrade.py2
1 files changed, 1 insertions, 1 deletions
diff --git a/ipaserver/install/server/upgrade.py b/ipaserver/install/server/upgrade.py
index ee357bb24..f9f2d75f9 100644
--- a/ipaserver/install/server/upgrade.py
+++ b/ipaserver/install/server/upgrade.py
@@ -1306,7 +1306,7 @@ def add_default_caacl(ca):
if not api.Command.caacl_find()['result']:
api.Command.caacl_add(u'hosts_services_caIPAserviceCert',
- hostcategory=u'all', usercategory=u'all')
+ hostcategory=u'all', servicecategory=u'all')
api.Command.caacl_add_profile(u'hosts_services_caIPAserviceCert',
certprofile=(u'caIPAserviceCert',))