diff options
| author | Nathaniel McCallum <npmccallum@redhat.com> | 2014-11-11 14:41:42 -0500 |
|---|---|---|
| committer | Petr Vobornik <pvoborni@redhat.com> | 2014-12-05 13:42:19 +0100 |
| commit | 9baa93da1cbf56c2a6f7e82e099bc3ff3f19e2e4 (patch) | |
| tree | 84108cff4ba380a6842ef3fe3f189b5c3f963135 /install/updates | |
| parent | bea417828d61777015785c716c4225bb48dcf037 (diff) | |
| download | freeipa-9baa93da1cbf56c2a6f7e82e099bc3ff3f19e2e4.tar.gz freeipa-9baa93da1cbf56c2a6f7e82e099bc3ff3f19e2e4.tar.xz freeipa-9baa93da1cbf56c2a6f7e82e099bc3ff3f19e2e4.zip | |
Make token auth and sync windows configurable
This introduces two new CLI commands:
* otpconfig-show
* otpconfig-mod
https://fedorahosted.org/freeipa/ticket/4511
Reviewed-By: Thierry Bordaz <tbordaz@redhat.com>
Reviewed-By: Petr Vobornik <pvoborni@redhat.com>
Diffstat (limited to 'install/updates')
| -rw-r--r-- | install/updates/40-otp.update | 9 |
1 files changed, 9 insertions, 0 deletions
diff --git a/install/updates/40-otp.update b/install/updates/40-otp.update index 83808b718..7cdff44ba 100644 --- a/install/updates/40-otp.update +++ b/install/updates/40-otp.update @@ -3,6 +3,15 @@ default: objectClass: nsContainer default: objectClass: top default: cn: otp +dn: cn=otp,cn=etc,$SUFFIX +default: objectClass: ipatokenOTPConfig +default: objectClass: top +default: cn: otp +default: ipatokenTOTPauthWindow: 300 +default: ipatokenTOTPsyncWindow: 86400 +default: ipatokenHOTPauthWindow: 10 +default: ipatokenHOTPsyncWindow: 100 + dn: $SUFFIX remove: aci:'(target = "ldap:///ipatokenuniqueid=*,cn=otp,$SUFFIX")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create and delete tokens"; allow (add, delete) userattr = "ipatokenOwner#SELFDN";)' remove: aci:'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN";)' |
