[Freeipa-devel] [PATCH] Password vault
Jan Cholasta
jcholast at redhat.com
Tue Jul 7 08:51:30 UTC 2015
Dne 3.7.2015 v 15:44 Endi Sukma Dewata napsal(a):
> Here is the rebased patch for vault access control.
>
LGTM, except:
@@ -356,6 +386,13 @@ class vault(LDAPObject):
{
'objectclass': ['nsContainer'],
'cn': rdn['cn'],
+ 'aci':
+ '(targetfilter="(objectClass=ipaVault)")' +
+ '(version 3.0; ' +
+ 'acl "User can manage private vaults"; ' +
+ 'allow(read, search, compare, add, delete) ' +
+ 'userdn="ldap:///%s";)'
+ % owner_dn
})
# if entry can be added, return
I don't think dynamically creating ACIs with hardcoded userdn is
something we want to do. This should be handled by a single ACI in
cn=vaults.
--
Jan Cholasta
More information about the Freeipa-devel
mailing list