summaryrefslogtreecommitdiffstats
path: root/install/updates
diff options
context:
space:
mode:
authorAna Krivokapic <akrivoka@redhat.com>2013-09-19 14:10:32 +0200
committerMartin Kosek <mkosek@redhat.com>2013-11-15 12:46:06 +0100
commitdfea5989f7edeb9ebc2d4fe42641e8818222761a (patch)
treea755782e5a20f00e8bcb9d9a710bfcd47110f21a /install/updates
parentd97386de5b68c90c53362dda54b126fdc97e00b6 (diff)
downloadfreeipa-dfea5989f7edeb9ebc2d4fe42641e8818222761a.tar.gz
freeipa-dfea5989f7edeb9ebc2d4fe42641e8818222761a.tar.xz
freeipa-dfea5989f7edeb9ebc2d4fe42641e8818222761a.zip
Add a privilege and a permission needed for automember rebuild command
Design: http://www.freeipa.org/page/V3/Automember_rebuild_membership https://fedorahosted.org/freeipa/ticket/3752
Diffstat (limited to 'install/updates')
-rw-r--r--install/updates/40-delegation.update19
1 files changed, 19 insertions, 0 deletions
diff --git a/install/updates/40-delegation.update b/install/updates/40-delegation.update
index 64a6432ac..3fabdf9c7 100644
--- a/install/updates/40-delegation.update
+++ b/install/updates/40-delegation.update
@@ -373,3 +373,22 @@ add: member: 'cn=Host Administrators,cn=privileges,cn=pbac,$SUFFIX'
dn: cn=Revoke Certificate,cn=permissions,cn=pbac,$SUFFIX
add: member: 'cn=Host Administrators,cn=privileges,cn=pbac,$SUFFIX'
+
+# Automember tasks
+dn: cn=Automember Task Administrator,cn=privileges,cn=pbac,$SUFFIX
+default:objectClass: nestedgroup
+default:objectClass: groupofnames
+default:objectClass: top
+default:cn: Automember Task Administrator
+default:description: Automember Task Administrator
+
+dn: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,$SUFFIX
+default:objectClass: groupofnames
+default:objectClass: ipapermission
+default:objectClass: top
+default:cn: Add Automember Rebuild Membership Task
+default:member: cn=Automember Task Administrator,cn=privileges,cn=pbac,$SUFFIX
+default:ipapermissiontype: SYSTEM
+
+dn: cn=config
+add:aci: '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,$SUFFIX";)'