2013-02-21 09:56:03 -06:00
|
|
|
# Authors:
|
|
|
|
# Ana Krivokapic <akrivoka@redhat.com>
|
|
|
|
#
|
|
|
|
# Copyright (C) 2013 Red Hat
|
|
|
|
# see file 'COPYING' for use and warranty information
|
|
|
|
#
|
|
|
|
# This program is free software; you can redistribute it and/or modify
|
|
|
|
# it under the terms of the GNU General Public License as published by
|
|
|
|
# the Free Software Foundation, either version 3 of the License, or
|
|
|
|
# (at your option) any later version.
|
|
|
|
#
|
|
|
|
# This program is distributed in the hope that it will be useful,
|
|
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
# GNU General Public License for more details.
|
|
|
|
#
|
|
|
|
# You should have received a copy of the GNU General Public License
|
|
|
|
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
"""
|
|
|
|
Test adding/removing external members (trusted domain objects) to IPA groups.
|
|
|
|
These tests are skipped if trust is not established.
|
|
|
|
"""
|
|
|
|
|
|
|
|
from ipalib import api
|
|
|
|
from ipapython.dn import DN
|
2013-05-21 06:40:27 -05:00
|
|
|
from ipatests.test_xmlrpc import objectclasses
|
2015-07-31 03:15:01 -05:00
|
|
|
from ipatests.test_xmlrpc.xmlrpc_test import (Declarative, fuzzy_uuid,
|
|
|
|
fuzzy_user_or_group_sid)
|
2015-04-24 07:39:48 -05:00
|
|
|
import pytest
|
2013-02-21 09:56:03 -06:00
|
|
|
|
|
|
|
group_name = u'external_group'
|
|
|
|
group_desc = u'Test external group'
|
|
|
|
group_dn = DN(('cn', group_name), api.env.container_group, api.env.basedn)
|
|
|
|
|
|
|
|
|
|
|
|
def get_trusted_group_name():
|
|
|
|
trusts = api.Command['trust_find']()
|
|
|
|
if trusts['count'] == 0:
|
|
|
|
return None
|
|
|
|
|
|
|
|
ad_netbios = trusts['result'][0]['ipantflatname']
|
2019-09-23 16:30:22 -05:00
|
|
|
return r'%s\Domain Admins' % ad_netbios
|
2013-02-21 09:56:03 -06:00
|
|
|
|
|
|
|
|
2015-04-24 07:39:48 -05:00
|
|
|
@pytest.mark.tier1
|
2013-02-21 09:56:03 -06:00
|
|
|
class test_external_members(Declarative):
|
2019-06-20 09:14:02 -05:00
|
|
|
@pytest.fixture(autouse=True, scope="class")
|
|
|
|
def ext_member_setup(self, declarative_setup):
|
2012-12-19 03:25:24 -06:00
|
|
|
if not api.Backend.rpcclient.isconnected():
|
2016-05-25 05:31:03 -05:00
|
|
|
api.Backend.rpcclient.connect()
|
2013-02-21 09:56:03 -06:00
|
|
|
|
|
|
|
trusts = api.Command['trust_find']()
|
|
|
|
if trusts['count'] == 0:
|
2019-10-15 05:24:11 -05:00
|
|
|
pytest.skip('Trust is not established')
|
2013-02-21 09:56:03 -06:00
|
|
|
|
|
|
|
cleanup_commands = [
|
|
|
|
('group_del', [group_name], {}),
|
|
|
|
]
|
|
|
|
|
|
|
|
tests = [
|
|
|
|
dict(
|
|
|
|
desc='Create external group "%s"' % group_name,
|
|
|
|
command=(
|
|
|
|
'group_add', [group_name], dict(description=group_desc, external=True)
|
|
|
|
),
|
|
|
|
expected=dict(
|
|
|
|
value=group_name,
|
|
|
|
summary=u'Added group "%s"' % group_name,
|
|
|
|
result=dict(
|
|
|
|
cn=[group_name],
|
|
|
|
description=[group_desc],
|
|
|
|
objectclass=objectclasses.externalgroup,
|
|
|
|
ipauniqueid=[fuzzy_uuid],
|
|
|
|
dn=group_dn,
|
|
|
|
),
|
|
|
|
),
|
|
|
|
),
|
|
|
|
dict(
|
|
|
|
desc='Add external member "%s" to group "%s"' % (get_trusted_group_name(), group_name),
|
|
|
|
command=(
|
|
|
|
'group_add_member', [group_name], dict(ipaexternalmember=get_trusted_group_name())
|
|
|
|
),
|
|
|
|
expected=dict(
|
|
|
|
completed=1,
|
|
|
|
failed=dict(
|
|
|
|
member=dict(
|
|
|
|
group=tuple(),
|
|
|
|
user=tuple(),
|
|
|
|
),
|
|
|
|
),
|
|
|
|
result=dict(
|
|
|
|
dn=group_dn,
|
|
|
|
ipaexternalmember=[fuzzy_user_or_group_sid],
|
|
|
|
cn=[group_name],
|
|
|
|
description=[group_desc],
|
|
|
|
),
|
|
|
|
),
|
|
|
|
),
|
|
|
|
dict(
|
|
|
|
desc='Try to add duplicate external member "%s" to group "%s"' % (get_trusted_group_name(), group_name),
|
|
|
|
command=(
|
|
|
|
'group_add_member', [group_name], dict(ipaexternalmember=get_trusted_group_name())
|
|
|
|
),
|
|
|
|
expected=dict(
|
|
|
|
completed=0,
|
|
|
|
failed=dict(
|
|
|
|
member=dict(
|
|
|
|
group=[(fuzzy_user_or_group_sid, u'This entry is already a member')],
|
|
|
|
user=tuple(),
|
|
|
|
),
|
|
|
|
),
|
|
|
|
result=dict(
|
|
|
|
dn=group_dn,
|
|
|
|
ipaexternalmember=[fuzzy_user_or_group_sid],
|
|
|
|
cn=[group_name],
|
|
|
|
description=[group_desc],
|
|
|
|
),
|
|
|
|
),
|
|
|
|
),
|
|
|
|
dict(
|
|
|
|
desc='Remove external member "%s" from group "%s"' % (get_trusted_group_name(), group_name),
|
|
|
|
command=(
|
|
|
|
'group_remove_member', [group_name], dict(ipaexternalmember=get_trusted_group_name())
|
|
|
|
),
|
|
|
|
expected=dict(
|
|
|
|
completed=1,
|
|
|
|
failed=dict(
|
|
|
|
member=dict(
|
|
|
|
group=tuple(),
|
|
|
|
user=tuple(),
|
|
|
|
),
|
|
|
|
),
|
|
|
|
result=dict(
|
|
|
|
dn=group_dn,
|
|
|
|
cn=[group_name],
|
|
|
|
ipaexternalmember=[],
|
|
|
|
description=[group_desc],
|
|
|
|
),
|
|
|
|
),
|
|
|
|
),
|
|
|
|
dict(
|
|
|
|
desc='Try to remove external entry "%s" which is not a member of group "%s" from group "%s"' % (get_trusted_group_name(), group_name, group_name),
|
|
|
|
command=(
|
|
|
|
'group_remove_member', [group_name], dict(ipaexternalmember=get_trusted_group_name())
|
|
|
|
),
|
|
|
|
expected=dict(
|
|
|
|
completed=0,
|
|
|
|
failed=dict(
|
|
|
|
member=dict(
|
|
|
|
group=[(fuzzy_user_or_group_sid, u'This entry is not a member')],
|
|
|
|
user=tuple(),
|
|
|
|
),
|
|
|
|
),
|
|
|
|
result=dict(
|
|
|
|
dn=group_dn,
|
|
|
|
cn=[group_name],
|
|
|
|
description=[group_desc],
|
|
|
|
),
|
|
|
|
),
|
|
|
|
),
|
|
|
|
]
|