From a91c0972b992dbd15e78f2ba6982768ac958e4bd Mon Sep 17 00:00:00 2001 From: Nathaniel McCallum Date: Thu, 6 Feb 2014 11:27:29 -0500 Subject: Update ACIs to permit users to add/delete their own tokens https://fedorahosted.org/freeipa/ticket/4087 Reviewed-By: Alexander Bokovoy --- install/updates/40-otp.update | 1 + 1 file changed, 1 insertion(+) (limited to 'install/updates') diff --git a/install/updates/40-otp.update b/install/updates/40-otp.update index 83dfab7c0..8e1300fb3 100644 --- a/install/updates/40-otp.update +++ b/install/updates/40-otp.update @@ -7,6 +7,7 @@ dn: $SUFFIX add: aci:'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN";)' add: aci:'(targetfilter = "(objectClass=ipaToken)")(targetattrs = "ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can write basic token info"; allow (write) userattr = "ipatokenOwner#USERDN";)' add: aci:'(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPclockOffset || ipatokenTOTPtimeStep")(version 3.0; acl "Users can add TOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' +add: aci:'(target = "ldap:///ipatokenuniqueid=*,cn=otp,$SUFFIX")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create and delete tokens"; allow (add, delete) userattr = "ipatokenOwner#SELFDN";)' dn: cn=radiusproxy,$SUFFIX default: objectClass: nsContainer -- cgit