<html>
<head>
<style><!--
.hmmessage P
{
margin:0px;
padding:0px
}
body.hmmessage
{
font-size: 12pt;
font-family:Calibri
}
--></style></head>
<body class='hmmessage'><div dir='ltr'>Hi All,<div><br></div><div>I have created below permission for my "<span style="font-size: 12pt;">testhostgroup" with the </span>expectation<span style="font-size: 12pt;"> that this permission will only allow write </span>permission<span style="font-size: 12pt;"> to the members of "</span><span style="font-size: 12pt;">testhostgroup" but, then it allows me to add/delete other hostgroup members as well. I tried changing the effective attribute to "<b>memberof</b>" instead of "member" but in vain as with that i started getting permission denied error even on </span><span style="font-size: 12pt;">testhostgroup itself.</span></div><div><br></div><div>*****</div><div>
<p class="p1"><span class="s1">ipa permission-add 'testhostgroup-modify' --permission=write --attrs=member --filter='(&(cn=testhostgroup)(objectclass=ipahostgroup ))'</span></p>
<p class="p1"><span class="s1">--------------------------------------</span></p>
<p class="p1"><span class="s1">Added permission "testhostgroup-modify"</span></p>
<p class="p1"><span class="s1">--------------------------------------</span></p>
<p class="p1"><span class="s1"> Permission name: testhostgroup-modify</span></p>
<p class="p1"><span class="s1"> Granted rights: write</span></p>
<p class="p1"><span class="s1"> Effective attributes: <b>member</b></span></p>
<p class="p1"><span class="s1"> Bind rule type: permission</span></p>
<p class="p1"><span class="s1"> Subtree: dc=us-west-2,dc=compute,dc=amazonaws,dc=com</span></p>
<p class="p1"><span class="s1"> Extra target filter: (&(cn= testhostgroup)(objectclass=ipahostgroup ))</span></p><p class="p1"><span class="s1">******</span></p><p class="p1"><span class="s1"><br></span></p><p class="p1"><span class="s1">How can i restrict permissions to manage only those hosts which are part of a particular hostgroup? any help you could offer on this would be much appreciated. I could not find much on similar issue in the forum :(</span></p><p class="p1"><span class="s1"><br></span></p><p class="p1"><span class="s1">Thanks,</span></p><p class="p1"><span class="s1">Deepak</span></p></div> </div></body>
</html>