summaryrefslogtreecommitdiffstats
path: root/ipaserver/install/plugins/update_anonymous_aci.py
diff options
context:
space:
mode:
authorPetr Viktorin <pviktori@redhat.com>2014-04-29 21:32:29 +0200
committerPetr Viktorin <pviktori@redhat.com>2014-05-26 12:12:35 +0200
commit63becae88c6c270b98f0432dc474b661b82f3119 (patch)
tree42215fed49d231ae59f51848279ec88b677419db /ipaserver/install/plugins/update_anonymous_aci.py
parent993c1c8557aafb890199b1c443ebd2d895ae6ba6 (diff)
downloadfreeipa-63becae88c6c270b98f0432dc474b661b82f3119.tar.gz
freeipa-63becae88c6c270b98f0432dc474b661b82f3119.tar.xz
freeipa-63becae88c6c270b98f0432dc474b661b82f3119.zip
Set user addressbook/IPA attribute read ACI to anonymous on upgrades from 3.x
When upgrading from an "old" IPA, or installing the first "new" replica, we need to keep allowing anonymous access to many user attributes. Add an optional 'fixup_function' to the managed permission templates, and use it to set the bind rule type to 'anonymous' when installing (or upgrading to) the first "new" master. This assumes that the anonymous read ACI will be removed in a "new" IPA. Part of the work for: https://fedorahosted.org/freeipa/ticket/3566 Reviewed-By: Martin Kosek <mkosek@redhat.com>
Diffstat (limited to 'ipaserver/install/plugins/update_anonymous_aci.py')
0 files changed, 0 insertions, 0 deletions