[Freeipa-devel] [PATCH] 0616 Allow read access to services in cn=masters to auth'd users

Petr Viktorin pviktori at redhat.com
Fri Jul 4 12:49:33 UTC 2014


Hello,

The dns-is-enabled command, used by the Web UI to determine if DNS pages 
should be displayed, queries '(&(objectClass=ipaConfigObject)(cn=DNS))' 
in cn=masters. However, currently the service entries are not accessible 
to all users, so the check will fail for non-admins.

We talked about this with Martin and agreed that there's no sensitive 
information in the service entries.
This patch grants read access to all authenticated users.

Simo, is this OK?

-- 
Petr³
-------------- next part --------------
A non-text attachment was scrubbed...
Name: freeipa-pviktori-0616-Allow-read-access-to-services-in-cn-masters-to-auth-.patch
Type: text/x-patch
Size: 1477 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20140704/abdfabad/attachment.bin>


More information about the Freeipa-devel mailing list