diff options
author | Jr Aquino <jr.aquino@citrix.com> | 2011-01-27 15:15:15 -0800 |
---|---|---|
committer | Adam Young <ayoung@redhat.com> | 2011-01-27 22:22:38 -0500 |
commit | 7b04b2240b92cc586fc06a8686c3616b020137fe (patch) | |
tree | f4e4dd5f140c5fde6a81ac65e9f8027e8c4f7fa3 /install/share | |
parent | 3cb33d74aecbd122e61cffd8226ea84389c15951 (diff) | |
download | freeipa-7b04b2240b92cc586fc06a8686c3616b020137fe.tar.gz freeipa-7b04b2240b92cc586fc06a8686c3616b020137fe.tar.xz freeipa-7b04b2240b92cc586fc06a8686c3616b020137fe.zip |
block anonymous access to sudo info https://fedorahosted.org/freeipa/ticket/865
Diffstat (limited to 'install/share')
-rw-r--r-- | install/share/default-aci.ldif | 6 |
1 files changed, 6 insertions, 0 deletions
diff --git a/install/share/default-aci.ldif b/install/share/default-aci.ldif index 8b00f4609..5a9d6e2fc 100644 --- a/install/share/default-aci.ldif +++ b/install/share/default-aci.ldif @@ -13,6 +13,7 @@ aci: (targetattr = "userPassword || krbPrincipalKey || krbPasswordExpiration || aci: (targetattr = "krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount")(version 3.0; acl "KDC System Account can update some fields"; allow (write) userdn="ldap:///uid=kdc,cn=sysaccounts,cn=etc,$SUFFIX";) aci: (targetattr = "krbPrincipalName || krbCanonicalName || krbUPEnabled || krbMKey || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount")(version 3.0; acl "Only the KDC System Account has access to kerberos material"; allow (read, search, compare) userdn="ldap:///uid=kdc,cn=sysaccounts,cn=etc,$SUFFIX";) aci: (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,$SUFFIX";) +aci: (targetattr = "*")(target = "ldap:///cn=*,ou=SUDOers,$SUFFIX")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";) dn: cn=users,cn=accounts,$SUFFIX changetype: modify @@ -73,3 +74,8 @@ dn: cn=hbac,$SUFFIX changetype: modify add: aci aci: (targetattr = "*")(version 3.0; acl "No anonymous access to hbac"; deny (read,search,compare) userdn != "ldap:///all";) + +dn: cn=sudo,$SUFFIX +changetype: modify +add: aci +aci: (targetattr = "*")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";) |