summaryrefslogtreecommitdiffstats
path: root/ACI.txt
diff options
context:
space:
mode:
authorAlexander Bokovoy <abokovoy@redhat.com>2014-09-30 15:44:31 +0300
committerPetr Vobornik <pvoborni@redhat.com>2014-10-13 12:08:50 +0200
commit63be2ee9f0296e1366c77258929c7ce2dad53154 (patch)
tree5cacce85daa739cdb7a9aed67c0ea9071881c574 /ACI.txt
parent35c7bd05afd9b1c5d3f3b0049773535e65b8d080 (diff)
downloadfreeipa-63be2ee9f0296e1366c77258929c7ce2dad53154.tar.gz
freeipa-63be2ee9f0296e1366c77258929c7ce2dad53154.tar.xz
freeipa-63be2ee9f0296e1366c77258929c7ce2dad53154.zip
Support overridding user shell in ID views
Reviewed-By: Petr Vobornik <pvoborni@redhat.com>
Diffstat (limited to 'ACI.txt')
-rw-r--r--ACI.txt2
1 files changed, 1 insertions, 1 deletions
diff --git a/ACI.txt b/ACI.txt
index cebdc2cce..25f3c7228 100644
--- a/ACI.txt
+++ b/ACI.txt
@@ -121,7 +121,7 @@ aci: (targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:S
dn: cn=views,cn=accounts,dc=ipa,dc=example
aci: (targetattr = "cn || createtimestamp || description || entryusn || gidnumber || ipaanchoruuid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaGroupOverride)")(version 3.0;acl "permission:System: Read Group ID Overrides";allow (compare,read,search) userdn = "ldap:///all";)
dn: cn=views,cn=accounts,dc=ipa,dc=example
-aci: (targetattr = "createtimestamp || description || entryusn || homedirectory || ipaanchoruuid || ipaoriginaluid || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaUserOverride)")(version 3.0;acl "permission:System: Read User ID Overrides";allow (compare,read,search) userdn = "ldap:///all";)
+aci: (targetattr = "createtimestamp || description || entryusn || homedirectory || ipaanchoruuid || ipaoriginaluid || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaUserOverride)")(version 3.0;acl "permission:System: Read User ID Overrides";allow (compare,read,search) userdn = "ldap:///all";)
dn: cn=ranges,cn=etc,dc=ipa,dc=example
aci: (targetattr = "cn || createtimestamp || entryusn || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";)
dn: cn=views,cn=accounts,dc=ipa,dc=example