[Freeipa-users] HBAC and SUDO rules for legacy clients

Alexander Bokovoy abokovoy at redhat.com
Mon Apr 20 15:03:08 UTC 2015


On Mon, 20 Apr 2015, Srdjan Dutina wrote:
>Just found in
>http://www.freeipa.org/images/0/0d/FreeIPA33-legacy-clients.pdf the next
>sentence: "If you have HBAC's allow_all rule disabled, you will need to
>allow system-auth service on the FreeIPA  master, so that authentication of
>the AD users can be performed."
>Is this true for FreeIPA 4.1.0 also and how could I do this?
Either you are reading it wrong or I don't get where you want to apply
HBAC rules because this is for IPA masters, not legacy clients per se.
Yes, you nede to create HBAC service named 'system-auth' and grant
access to it to AD users on IPA masters, but all it will allow you is to
authenticate AD users via compat tree.

If your RHEL5 SSSD clients attempt to run own HBAC rule checks, AD users
cannot be checked by those rules.



-- 
/ Alexander Bokovoy




More information about the Freeipa-users mailing list