Files
freeipa/ipalib/plugins/config.py
T

318 lines
12 KiB
Python
Raw Normal View History

# Authors:
# Rob Crittenden <rcritten@redhat.com>
# Pavel Zuna <pzuna@redhat.com>
#
# Copyright (C) 2008 Red Hat
# see file 'COPYING' for use and warranty information
#
2010-12-09 13:59:11 +01:00
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation, either version 3 of the License, or
# (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
2010-12-09 13:59:11 +01:00
# along with this program. If not, see <http://www.gnu.org/licenses/>.
from ipalib import api
2012-05-13 07:36:35 -04:00
from ipalib import Bool, Int, Str, IA5Str, StrEnum, DNParam
from ipalib.plugins.baseldap import *
2012-09-25 13:46:56 +02:00
from ipalib.plugins.selinuxusermap import validate_selinuxuser
from ipalib import _
from ipalib.errors import ValidationError
# 389-ds attributes that should be skipped in attribute checks
OPERATIONAL_ATTRIBUTES = ('nsaccountlock', 'member', 'memberof',
'memberindirect', 'memberofindirect',)
__doc__ = _("""
2011-11-10 12:06:49 +01:00
Server configuration
2010-06-02 14:08:50 -04:00
Manage the default values that IPA uses and some of its tuning parameters.
2010-06-02 14:08:50 -04:00
2011-11-10 12:06:49 +01:00
NOTES:
2010-06-02 14:08:50 -04:00
2011-11-10 12:06:49 +01:00
The password notification value (--pwdexpnotify) is stored here so it will
be replicated. It is not currently used to notify users in advance of an
expiring password.
2010-06-02 14:08:50 -04:00
2011-11-10 12:06:49 +01:00
Some attributes are read-only, provided only for information purposes. These
include:
2010-06-02 14:08:50 -04:00
2011-11-10 12:06:49 +01:00
Certificate Subject base: the configured certificate subject base,
e.g. O=EXAMPLE.COM. This is configurable only at install time.
Password plug-in features: currently defines additional hashes that the
password will generate (there may be other conditions).
2010-06-02 14:08:50 -04:00
2011-11-23 16:59:21 -05:00
When setting the order list for mapping SELinux users you may need to
quote the value so it isn't interpreted by the shell.
2011-11-10 12:06:49 +01:00
EXAMPLES:
2010-06-02 14:08:50 -04:00
2011-11-10 12:06:49 +01:00
Show basic server configuration:
ipa config-show
2010-06-02 14:08:50 -04:00
2011-11-10 12:06:49 +01:00
Show all configuration options:
ipa config-show --all
2010-06-02 14:08:50 -04:00
2011-11-10 12:06:49 +01:00
Change maximum username length to 99 characters:
ipa config-mod --maxusername=99
2010-06-02 14:08:50 -04:00
2011-11-10 12:06:49 +01:00
Increase default time and size limits for maximum IPA server search:
ipa config-mod --searchtimelimit=10 --searchrecordslimit=2000
2011-11-10 12:06:49 +01:00
Set default user e-mail domain:
ipa config-mod --emaildomain=example.com
2011-11-10 12:06:49 +01:00
Enable migration mode to make "ipa migrate-ds" command operational:
ipa config-mod --enable-migration=TRUE
2011-11-23 16:59:21 -05:00
Define SELinux user map order:
ipa config-mod --ipaselinuxusermaporder='guest_u:s0$xguest_u:s0$user_u:s0-s0:c0.c1023$staff_u:s0-s0:c0.c1023$unconfined_u:s0-s0:c0.c1023'
""")
def validate_searchtimelimit(ugettext, limit):
if limit == 0:
raise ValidationError(name='ipasearchtimelimit', error=_('searchtimelimit must be -1 or > 1.'))
return None
class config(LDAPObject):
"""
IPA configuration object
"""
object_name = _('configuration options')
default_attributes = [
'ipamaxusernamelength', 'ipahomesrootdir', 'ipadefaultloginshell',
'ipadefaultprimarygroup', 'ipadefaultemaildomain', 'ipasearchtimelimit',
'ipasearchrecordslimit', 'ipausersearchfields', 'ipagroupsearchfields',
2010-01-20 11:26:20 -05:00
'ipamigrationenabled', 'ipacertificatesubjectbase',
2012-01-19 17:42:26 -05:00
'ipapwdexpadvnotify', 'ipaselinuxusermaporder',
'ipaselinuxusermapdefault', 'ipaconfigstring', 'ipakrbauthzdata',
]
2010-09-24 20:48:23 -04:00
label = _('Configuration')
2011-07-13 21:10:47 -05:00
label_singular = _('Configuration')
2010-09-24 20:48:23 -04:00
takes_params = (
2012-02-20 04:03:27 -05:00
Int('ipamaxusernamelength',
cli_name='maxusername',
2011-11-10 12:06:49 +01:00
label=_('Maximum username length'),
minvalue=1,
),
2012-02-20 04:03:27 -05:00
IA5Str('ipahomesrootdir',
cli_name='homedirectory',
2010-02-19 09:08:16 -07:00
label=_('Home directory base'),
2011-11-10 12:06:49 +01:00
doc=_('Default location of home directories'),
),
2012-02-20 04:03:27 -05:00
Str('ipadefaultloginshell',
cli_name='defaultshell',
2010-02-19 09:08:16 -07:00
label=_('Default shell'),
2011-11-10 12:06:49 +01:00
doc=_('Default shell for new users'),
),
2012-02-20 04:03:27 -05:00
Str('ipadefaultprimarygroup',
cli_name='defaultgroup',
2010-02-19 09:08:16 -07:00
label=_('Default users group'),
2011-11-10 12:06:49 +01:00
doc=_('Default group for new users'),
),
Str('ipadefaultemaildomain?',
cli_name='emaildomain',
2011-11-10 12:06:49 +01:00
label=_('Default e-mail domain'),
doc=_('Default e-mail domain'),
),
2012-02-20 04:03:27 -05:00
Int('ipasearchtimelimit', validate_searchtimelimit,
cli_name='searchtimelimit',
2010-02-19 09:08:16 -07:00
label=_('Search time limit'),
2011-11-10 12:06:49 +01:00
doc=_('Maximum amount of time (seconds) for a search (> 0, or -1 for unlimited)'),
minvalue=-1,
),
2012-02-20 04:03:27 -05:00
Int('ipasearchrecordslimit',
cli_name='searchrecordslimit',
2010-02-19 09:08:16 -07:00
label=_('Search size limit'),
2011-11-10 12:06:49 +01:00
doc=_('Maximum number of records to search (-1 is unlimited)'),
minvalue=-1,
),
2012-02-20 04:03:27 -05:00
IA5Str('ipausersearchfields',
cli_name='usersearch',
2010-02-19 09:08:16 -07:00
label=_('User search fields'),
2011-11-10 12:06:49 +01:00
doc=_('A comma-separated list of fields to search in when searching for users'),
),
2012-02-20 04:03:27 -05:00
IA5Str('ipagroupsearchfields',
cli_name='groupsearch',
2010-01-20 11:26:20 -05:00
label='Group search fields',
2011-11-10 12:06:49 +01:00
doc=_('A comma-separated list of fields to search in when searching for groups'),
),
2012-02-20 04:03:27 -05:00
Bool('ipamigrationenabled',
cli_name='enable_migration',
label=_('Enable migration mode'),
2011-11-10 12:06:49 +01:00
doc=_('Enable migration mode'),
),
2012-05-13 07:36:35 -04:00
DNParam('ipacertificatesubjectbase',
2010-01-20 11:26:20 -05:00
cli_name='subject',
2010-02-19 09:08:16 -07:00
label=_('Certificate Subject base'),
2011-11-10 12:06:49 +01:00
doc=_('Base for certificate subjects (OU=Test,O=Example)'),
flags=['no_update'],
),
2012-02-20 04:03:27 -05:00
Str('ipagroupobjectclasses+',
cli_name='groupobjectclasses',
label=_('Default group objectclasses'),
2011-11-10 12:06:49 +01:00
doc=_('Default group objectclasses (comma-separated list)'),
csv=True,
),
2012-02-20 04:03:27 -05:00
Str('ipauserobjectclasses+',
cli_name='userobjectclasses',
label=_('Default user objectclasses'),
2011-11-10 12:06:49 +01:00
doc=_('Default user objectclasses (comma-separated list)'),
csv=True,
),
2012-02-20 04:03:27 -05:00
Int('ipapwdexpadvnotify',
cli_name='pwdexpnotify',
2011-07-05 14:55:03 -04:00
label=_('Password Expiration Notification (days)'),
2011-11-10 12:06:49 +01:00
doc=_('Number of days\'s notice of impending password expiration'),
minvalue=0,
),
2012-01-19 17:42:26 -05:00
StrEnum('ipaconfigstring*',
cli_name='ipaconfigstring',
label=_('Password plugin features'),
2011-11-10 12:06:49 +01:00
doc=_('Extra hashes to generate in password plug-in'),
2012-05-23 12:35:44 -04:00
values=(u'AllowLMhash', u'AllowNThash',
u'KDC:Disable Last Success', u'KDC:Disable Lockout'),
2012-01-19 17:42:26 -05:00
csv=True,
2010-01-20 11:26:20 -05:00
),
2012-02-20 04:03:27 -05:00
Str('ipaselinuxusermaporder',
2011-11-23 16:59:21 -05:00
label=_('SELinux user map order'),
doc=_('Order in increasing priority of SELinux users, delimited by $'),
),
Str('ipaselinuxusermapdefault?',
2011-11-23 16:59:21 -05:00
label=_('Default SELinux user'),
doc=_('Default SELinux user when no match is found in SELinux map rule'),
),
StrEnum('ipakrbauthzdata*',
cli_name='pac_type',
2012-10-02 17:06:10 +02:00
label=_('Default PAC types'),
doc=_('Default types of PAC supported for services'),
2013-03-04 14:52:10 +01:00
values=(u'MS-PAC', u'PAD', u'nfs:NONE'),
csv=True,
),
)
def get_dn(self, *keys, **kwargs):
2013-02-04 09:47:00 +01:00
return DN(('cn', 'ipaconfig'), ('cn', 'etc'), api.env.basedn)
api.register(config)
class config_mod(LDAPUpdate):
__doc__ = _('Modify configuration options.')
def pre_callback(self, ldap, dn, entry_attrs, attrs_list, *keys, **options):
2012-05-13 07:36:35 -04:00
assert isinstance(dn, DN)
2010-12-06 17:08:10 +01:00
if 'ipadefaultprimarygroup' in entry_attrs:
group=entry_attrs['ipadefaultprimarygroup']
try:
api.Object['group'].get_dn_if_exists(group)
2010-12-06 17:08:10 +01:00
except errors.NotFound:
2011-10-11 11:30:48 +02:00
raise errors.NotFound(message=_("The group doesn't exist"))
kw = {}
if 'ipausersearchfields' in entry_attrs:
kw['ipausersearchfields'] = 'ipauserobjectclasses'
if 'ipagroupsearchfields' in entry_attrs:
kw['ipagroupsearchfields'] = 'ipagroupobjectclasses'
if kw:
config = ldap.get_ipa_config(kw.values())
for (k, v) in kw.iteritems():
allowed_attrs = ldap.get_allowed_attributes(config[1][v])
fields = entry_attrs[k].split(',')
for a in fields:
a = a.strip()
if a not in allowed_attrs:
raise errors.ValidationError(
2011-10-11 11:30:48 +02:00
name=k, error=_('attribute "%s" not allowed') % a
)
for (attr, obj) in (('ipauserobjectclasses', 'user'),
('ipagroupobjectclasses', 'group')):
if attr in entry_attrs:
if not entry_attrs[attr]:
raise errors.ValidationError(name=attr,
error=_('May not be empty'))
objectclasses = list(set(entry_attrs[attr]).union(
self.api.Object[obj].possible_objectclasses))
new_allowed_attrs = ldap.get_allowed_attributes(objectclasses,
raise_on_unknown=True)
checked_attrs = self.api.Object[obj].default_attributes
if self.api.Object[obj].uuid_attribute:
checked_attrs = checked_attrs + [self.api.Object[obj].uuid_attribute]
for obj_attr in checked_attrs:
if obj_attr in OPERATIONAL_ATTRIBUTES:
continue
if obj_attr in self.api.Object[obj].params and \
'virtual_attribute' in \
self.api.Object[obj].params[obj_attr].flags:
# skip virtual attributes
continue
if obj_attr not in new_allowed_attrs:
raise errors.ValidationError(name=attr,
2012-02-10 04:27:53 -05:00
error=_('%(obj)s default attribute %(attr)s would not be allowed!') \
% dict(obj=obj, attr=obj_attr))
2012-09-25 13:46:56 +02:00
if ('ipaselinuxusermapdefault' in entry_attrs or
'ipaselinuxusermaporder' in entry_attrs):
2011-11-23 16:59:21 -05:00
config = None
failedattr = 'ipaselinuxusermaporder'
2012-09-25 13:46:56 +02:00
if 'ipaselinuxusermapdefault' in entry_attrs:
defaultuser = entry_attrs['ipaselinuxusermapdefault']
failedattr = 'ipaselinuxusermapdefault'
2012-09-25 13:46:56 +02:00
# validate the new default user first
if defaultuser is not None:
error_message = validate_selinuxuser(_, defaultuser)
if error_message:
raise errors.ValidationError(name='ipaselinuxusermapdefault',
error=error_message)
2011-11-23 16:59:21 -05:00
else:
config = ldap.get_ipa_config()[1]
2012-09-25 13:46:56 +02:00
defaultuser = config.get('ipaselinuxusermapdefault', [None])[0]
2011-11-23 16:59:21 -05:00
2012-09-25 13:46:56 +02:00
if 'ipaselinuxusermaporder' in entry_attrs:
order = entry_attrs['ipaselinuxusermaporder']
userlist = order.split('$')
2012-09-25 13:46:56 +02:00
# validate the new user order first
for user in userlist:
if not user:
raise errors.ValidationError(name='ipaselinuxusermaporder',
error=_('A list of SELinux users delimited by $ expected'))
error_message = validate_selinuxuser(_, user)
if error_message:
error_message = _("SELinux user '%(user)s' is not "
"valid: %(error)s") % dict(user=user,
error=error_message)
raise errors.ValidationError(name='ipaselinuxusermaporder',
error=error_message)
2011-11-23 16:59:21 -05:00
else:
if not config:
config = ldap.get_ipa_config()[1]
order = config['ipaselinuxusermaporder']
userlist = order[0].split('$')
if defaultuser and defaultuser not in userlist:
raise errors.ValidationError(name=failedattr,
error=_('SELinux user map default user not in order list'))
2011-11-23 16:59:21 -05:00
return dn
2009-07-02 09:50:48 +02:00
api.register(config_mod)
class config_show(LDAPRetrieve):
__doc__ = _('Show the current configuration.')
api.register(config_show)