[Freeipa-devel] [PATCH] 0520 Add managed read permission to service

Petr Viktorin pviktori at redhat.com
Mon Apr 14 11:04:47 UTC 2014


Read access is given to all authenticated users.

Exposed attributes are:
[top]
   objectClass
[ipaObject]
   ipaUniqueID
[ipaService]
   managedBy
   memberOf
   ipaKrbAuthzData  (a.k.a. pac_type)
[pkiUser]
   userCertificate
[krbPrincipalAux]
   krbPrincipalName
   krbCanonicalName
   krbPrincipalAliases
   krbPrincipalExpiration
   krbPasswordExpiration
   krbLastPwdChange
[krbTicketPolicyAux] - none
[ipaKrbPrincipal]
   krbPrincipalName
   ipaKrbPrincipalAlias
[krbPrincipal]
   krbPrincipalName
   krbObjectReferences


Kerberos-related attributes were discussed for hosts here: 
http://www.redhat.com/archives/freeipa-devel/2014-April/msg00242.html

-- 
Petr³
-------------- next part --------------
A non-text attachment was scrubbed...
Name: freeipa-pviktori-0520-Add-managed-read-permissions-to-service.patch
Type: text/x-patch
Size: 1514 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20140414/0ff4cc3c/attachment.bin>


More information about the Freeipa-devel mailing list