[Freeipa-devel] [PATCH] Password vault

Jan Cholasta jcholast at redhat.com
Tue Jul 7 08:51:30 UTC 2015


Dne 3.7.2015 v 15:44 Endi Sukma Dewata napsal(a):
> Here is the rebased patch for vault access control.
>

LGTM, except:

@@ -356,6 +386,13 @@ class vault(LDAPObject):
                  {
                      'objectclass': ['nsContainer'],
                      'cn': rdn['cn'],
+                    'aci':
+                        '(targetfilter="(objectClass=ipaVault)")' +
+                        '(version 3.0; ' +
+                        'acl "User can manage private vaults"; ' +
+                        'allow(read, search, compare, add, delete) ' +
+                        'userdn="ldap:///%s";)'
+                        % owner_dn
                  })

              # if entry can be added, return

I don't think dynamically creating ACIs with hardcoded userdn is 
something we want to do. This should be handled by a single ACI in 
cn=vaults.

-- 
Jan Cholasta




More information about the Freeipa-devel mailing list