Create default disabled sudo bind user

Read access is denied to the sudo container for unauthenticated users.
This shared user can be used to provide authenticated access to the
sudo information.

https://fedorahosted.org/freeipa/ticket/998
This commit is contained in:
Jr Aquino
2011-02-23 11:37:07 -08:00
committed by Rob Crittenden
parent 523eaa9749
commit 1770750b8a
5 changed files with 36 additions and 3 deletions

View File

@@ -48,6 +48,7 @@ app_DATA = \
modrdn-krbprinc.ldif \
entryusn.ldif \
root-autobind.ldif \
sudobind.ldif \
$(NULL)
EXTRA_DIST = \

View File

@@ -0,0 +1,9 @@
#SUDO bind user
dn: uid=sudo,cn=sysaccounts,cn=etc,$SUFFIX
changetype: add
objectclass: account
objectclass: simplesecurityobject
uid: sudo
userPassword: $RANDOM_PASSWORD
passwordExpirationTime: 20380119031407Z
nsIdleTimeout: 0