[Freeipa-devel] [PATCH] group inactivation
Rob Crittenden
rcritten at redhat.com
Fri Nov 16 23:34:56 UTC 2007
Enable group inactivation by using the Class of Service plugin.
This adds 2 new groups: activated and inactivated.
If you, or a group you are a member of, is in inactivated then you are too.
If you, or a group you are a member of, is in the activated group, then
you are too.
In a fight between activated and inactivated, activated wins.
The DNs for doing this matching is case and white space sensitive.
The goal is to never have to actually set nsAccountLock in a user
directly but move them between these groups.
We need to decide where in the CLI this will happen. Right it is split
between ipa-deluser and ipa-usermod. To inactivate groups for now just
add the group to inactivate or active.
rob
-------------- next part --------------
A non-text attachment was scrubbed...
Name: freeipa-393-groupinact.patch
Type: text/x-patch
Size: 26956 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20071116/ba675695/attachment.bin>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3245 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20071116/ba675695/attachment-0001.bin>
More information about the Freeipa-devel
mailing list