summaryrefslogtreecommitdiffstats
path: root/ipapython
diff options
context:
space:
mode:
authorFraser Tweedale <ftweedal@redhat.com>2016-05-03 13:22:39 +1000
committerJan Cholasta <jcholast@redhat.com>2016-06-09 09:04:27 +0200
commitb584ffa4ac9c61bad9e4e05e5b39bd0503e39dcd (patch)
treecf7b46febc5072e5f3142eb24fd286909350e063 /ipapython
parent29d669fec18c089619c199d66195ec3b73df7ee1 (diff)
downloadfreeipa-b584ffa4ac9c61bad9e4e05e5b39bd0503e39dcd.tar.gz
freeipa-b584ffa4ac9c61bad9e4e05e5b39bd0503e39dcd.tar.xz
freeipa-b584ffa4ac9c61bad9e4e05e5b39bd0503e39dcd.zip
Add ACIs for Dogtag custodia client
The "dogtag/$HOSTNAME@$REALM" service principal uses Custodia to retrieve lightweight CA signing keys, and therefore needs search and read access to Custodia keys. Add an ACI to permit this. Also add ACIs to allow host principals to manage Dogtag custodia keys for the same host. Part of: https://fedorahosted.org/freeipa/ticket/4559 Reviewed-By: Jan Cholasta <jcholast@redhat.com>
Diffstat (limited to 'ipapython')
0 files changed, 0 insertions, 0 deletions