[Freeipa-devel] [freeipa PR#444][comment] Allow nsaccountlock to be searched in user-find commands

MartinBasti freeipa-github-notification at redhat.com
Tue Feb 28 16:49:36 UTC 2017


  URL: https://github.com/freeipa/freeipa/pull/444
Title: #444: Allow nsaccountlock to be searched in user-find commands

MartinBasti commented:
"""
@redhatrises IMO for new users we can always create that attribute in LDAP, that should limit bad behavior. I wouldn't add it to user-add, usually you wants to create an enabled user, for disabled you can use stage-user.  I hope that activating of stage user creates this attribute in LDAP as well.

However this need a discussion, if it is a proper approach is the right.

BTW you can open a new PR we shouldn't continue here.
"""

See the full comment at https://github.com/freeipa/freeipa/pull/444#issuecomment-283096060


More information about the Freeipa-devel mailing list