[Freeipa-users] HBAC and SUDO rules for legacy clients
Alexander Bokovoy
abokovoy at redhat.com
Mon Apr 20 15:03:08 UTC 2015
On Mon, 20 Apr 2015, Srdjan Dutina wrote:
>Just found in
>http://www.freeipa.org/images/0/0d/FreeIPA33-legacy-clients.pdf the next
>sentence: "If you have HBAC's allow_all rule disabled, you will need to
>allow system-auth service on the FreeIPA master, so that authentication of
>the AD users can be performed."
>Is this true for FreeIPA 4.1.0 also and how could I do this?
Either you are reading it wrong or I don't get where you want to apply
HBAC rules because this is for IPA masters, not legacy clients per se.
Yes, you nede to create HBAC service named 'system-auth' and grant
access to it to AD users on IPA masters, but all it will allow you is to
authenticate AD users via compat tree.
If your RHEL5 SSSD clients attempt to run own HBAC rule checks, AD users
cannot be checked by those rules.
--
/ Alexander Bokovoy
More information about the Freeipa-users
mailing list