mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2025-02-25 18:55:28 -06:00
Add a new ipaVirtualOperation objectClass to virtual operations
The entries are moved from the ldif file to an update file. Part of the work for: https://fedorahosted.org/freeipa/ticket/3566 Reviewed-By: Martin Kosek <mkosek@redhat.com>
This commit is contained in:
parent
260c5bd109
commit
baa72b68b1
@ -64,3 +64,4 @@ objectClasses: (2.16.840.1.113730.3.8.12.17 NAME 'ipaTrustedADDomainRange' SUP i
|
||||
objectClasses: (2.16.840.1.113730.3.8.12.19 NAME 'ipaUserAuthTypeClass' SUP top AUXILIARY DESC 'Class for authentication methods definition' MAY ipaUserAuthType X-ORIGIN 'IPA v3')
|
||||
objectClasses: (2.16.840.1.113730.3.8.12.20 NAME 'ipaUser' AUXILIARY MUST ( uid ) MAY ( userClass ) X-ORIGIN 'IPA v3' )
|
||||
objectClasses: (2.16.840.1.113730.3.8.12.21 NAME 'ipaPermissionV2' DESC 'IPA Permission objectclass, version 2' SUP ipaPermission AUXILIARY MUST ( ipaPermBindRuleType $ ipaPermLocation ) MAY ( ipaPermDefaultAttr $ ipaPermIncludedAttr $ ipaPermExcludedAttr $ ipaPermRight $ ipaPermTargetFilter $ ipaPermTarget ) X-ORIGIN 'IPA v3' )
|
||||
objectClasses: (2.16.840.1.113730.3.8.12.23 NAME 'ipaVirtualOperation' DESC 'IPA Virtual operation objectclass' SUP top AUXILIARY MUST ( cn ) X-ORIGIN 'IPA v3' )
|
||||
|
@ -647,12 +647,6 @@ objectClass: nsContainer
|
||||
cn: virtual operations
|
||||
|
||||
# Retrieve Certificate virtual op
|
||||
dn: cn=retrieve certificate,cn=virtual operations,cn=etc,$SUFFIX
|
||||
changetype: add
|
||||
objectClass: top
|
||||
objectClass: nsContainer
|
||||
cn: retrieve certificate
|
||||
|
||||
dn: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,$SUFFIX
|
||||
changetype: add
|
||||
objectClass: top
|
||||
@ -667,12 +661,6 @@ add: aci
|
||||
aci: (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,$SUFFIX" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,$SUFFIX";)
|
||||
|
||||
# Request Certificate virtual op
|
||||
dn: cn=request certificate,cn=virtual operations,cn=etc,$SUFFIX
|
||||
changetype: add
|
||||
objectClass: top
|
||||
objectClass: nsContainer
|
||||
cn: request certificate
|
||||
|
||||
dn: cn=Request Certificate,cn=permissions,cn=pbac,$SUFFIX
|
||||
changetype: add
|
||||
objectClass: top
|
||||
@ -687,12 +675,6 @@ add: aci
|
||||
aci: (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,$SUFFIX" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,$SUFFIX";)
|
||||
|
||||
# Request Certificate from different host virtual op
|
||||
dn: cn=request certificate different host,cn=virtual operations,cn=etc,$SUFFIX
|
||||
changetype: add
|
||||
objectClass: top
|
||||
objectClass: nsContainer
|
||||
cn: request certificate different host
|
||||
|
||||
dn: cn=Request Certificates from a different host,cn=permissions,cn=pbac,$SUFFIX
|
||||
changetype: add
|
||||
objectClass: top
|
||||
@ -707,12 +689,6 @@ add: aci
|
||||
aci: (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,$SUFFIX" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,$SUFFIX";)
|
||||
|
||||
# Certificate Status virtual op
|
||||
dn: cn=certificate status,cn=virtual operations,cn=etc,$SUFFIX
|
||||
changetype: add
|
||||
objectClass: top
|
||||
objectClass: nsContainer
|
||||
cn: certificate status
|
||||
|
||||
dn: cn=Get Certificates status from the CA,cn=permissions,cn=pbac,$SUFFIX
|
||||
changetype: add
|
||||
objectClass: top
|
||||
@ -727,12 +703,6 @@ add: aci
|
||||
aci: (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,$SUFFIX" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,$SUFFIX";)
|
||||
|
||||
# Revoke Certificate virtual op
|
||||
dn: cn=revoke certificate,cn=virtual operations,cn=etc,$SUFFIX
|
||||
changetype: add
|
||||
objectClass: top
|
||||
objectClass: nsContainer
|
||||
cn: revoke certificate
|
||||
|
||||
dn: cn=Revoke Certificate,cn=permissions,cn=pbac,$SUFFIX
|
||||
changetype: add
|
||||
objectClass: top
|
||||
@ -747,12 +717,6 @@ add: aci
|
||||
aci: (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,$SUFFIX" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,$SUFFIX";)
|
||||
|
||||
# Certificate Remove Hold virtual op
|
||||
dn: cn=certificate remove hold,cn=virtual operations,cn=etc,$SUFFIX
|
||||
changetype: add
|
||||
objectClass: top
|
||||
objectClass: nsContainer
|
||||
cn: certificate remove hold
|
||||
|
||||
dn: cn=Certificate Remove Hold,cn=permissions,cn=pbac,$SUFFIX
|
||||
changetype: add
|
||||
objectClass: top
|
||||
|
@ -394,6 +394,45 @@ dn: cn=config
|
||||
add:aci: '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,$SUFFIX";)'
|
||||
|
||||
|
||||
# Virtual operations
|
||||
|
||||
dn: cn=retrieve certificate,cn=virtual operations,cn=etc,$SUFFIX
|
||||
add:objectClass: ipaVirtualOperation
|
||||
default:objectClass: top
|
||||
default:objectClass: nsContainer
|
||||
default:cn: retrieve certificate
|
||||
|
||||
dn: cn=request certificate,cn=virtual operations,cn=etc,$SUFFIX
|
||||
add:objectClass: ipaVirtualOperation
|
||||
default:objectClass: top
|
||||
default:objectClass: nsContainer
|
||||
default:cn: request certificate
|
||||
|
||||
dn: cn=request certificate different host,cn=virtual operations,cn=etc,$SUFFIX
|
||||
add:objectClass: ipaVirtualOperation
|
||||
default:objectClass: top
|
||||
default:objectClass: nsContainer
|
||||
default:cn: request certificate different host
|
||||
|
||||
dn: cn=certificate status,cn=virtual operations,cn=etc,$SUFFIX
|
||||
add:objectClass: ipaVirtualOperation
|
||||
default:objectClass: top
|
||||
default:objectClass: nsContainer
|
||||
default:cn: certificate status
|
||||
|
||||
dn: cn=revoke certificate,cn=virtual operations,cn=etc,$SUFFIX
|
||||
add:objectClass: ipaVirtualOperation
|
||||
default:objectClass: top
|
||||
default:objectClass: nsContainer
|
||||
default:cn: revoke certificate
|
||||
|
||||
dn: cn=certificate remove hold,cn=virtual operations,cn=etc,$SUFFIX
|
||||
add:objectClass: ipaVirtualOperation
|
||||
default:objectClass: top
|
||||
default:objectClass: nsContainer
|
||||
default:cn: certificate remove hold
|
||||
|
||||
|
||||
# Read privileges
|
||||
dn: cn=RBAC Readers,cn=privileges,cn=pbac,$SUFFIX
|
||||
default:objectClass: nestedgroup
|
||||
|
Loading…
Reference in New Issue
Block a user