[Freeipa-devel] [PATCH] 0504 Default read ACIs for Sudo objects

Petr Viktorin pviktori at redhat.com
Tue Apr 8 09:03:17 UTC 2014


On 04/07/2014 01:30 PM, Martin Kosek wrote:
> On 04/03/2014 12:09 PM, Petr Viktorin wrote:
>> Hello,
>> This adds read permissions to read Sudo commands, command groups, rules.
>>
>> Read access is given to all authenticated users.
>
> Looks good. What about "ou=sudoers"? I think we should also allow it in this
> patch for authenticated users. This is the tree that clients use to read sudo.

This new version does that. It needs my patches 0508-0509 since the 
ou=sudoers permission is not tied to a specific Object plugin.

-- 
Petr³
-------------- next part --------------
A non-text attachment was scrubbed...
Name: freeipa-pviktori-0504.2-Add-managed-read-permissions-to-Sudo-objects-and-ou-.patch
Type: text/x-patch
Size: 5968 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20140408/2df8394a/attachment.bin>


More information about the Freeipa-devel mailing list