JR Aquino
cfe18944d6
Allow PKI-CA Replica Installs when CRL exceeds default maxber value
...
https://fedorahosted.org/freeipa/ticket/3314
2013-01-08 10:52:50 -05:00
JR Aquino
714b0d11ec
Replication: Adjust replica installation to omit processing memberof computations
...
https://fedorahosted.org/freeipa/ticket/1794
If the master does not yet support the total update list feature we still
run the memberof fixup task and not fail to replicate due to the new
attribute not being settable.
Jointly-developed-with: Simo Sorce <ssorce@redhat.com >
Jointly-developed-with: Nathank Kinder <nkinder@redhat.com >
2011-11-14 05:30:06 -05:00
JR Aquino
1ac613fc18
25 Create Tool for Enabling/Disabling Managed Entry Plugins
...
Remove legacy ipa-host-net-manage
Add ipa-managed-entries tool
Add man page for ipa-managed-entries tool
https://fedorahosted.org/freeipa/ticket/1181
2011-09-21 09:22:13 +02:00
Jr Aquino
8b3336ef55
Move Managed Entries into their own container in the replicated space.
...
Repoint cn=Managed Entries,cn=plugins,cn=config in common_setup
Create: cn=Managed Entries,cn=etc,$SUFFIX
Create: cn=Definitions,cn=Managed Entries,cn=etc,$SUFFIX
Create: cn=Templates,cn=Managed Entries,cn=etc,$SUFFIX
Create method for dynamically migrating any and all custom Managed Entries
from the cn=config space into the new container.
Separate the connection creation during update so that a restart can
be performed to initialize changes before performing a delete.
Add wait_for_open_socket() method in installutils
https://fedorahosted.org/freeipa/ticket/1708
2011-09-12 16:28:27 -04:00
Jr Aquino
d05ace8fba
34 Create FreeIPA CLI Plugin for the 389 Auto Membership plugin
...
Added new container in etc to hold the automembership configs.
Modified constants to point to the new container
Modified dsinstance to create the container
Created automember.py to add the new commands
Added xmlrpc test to verify functionality
Added minor fix to user.py for constant behavior between memberof
and automember
https://fedorahosted.org/freeipa/ticket/1272
2011-08-31 09:49:43 +02:00
Jr Aquino
1077343d1a
Improve sudorule documentation
...
Added brief explanations for the various Sudo components in the
top level doc. Added doc entries for RunAs User and RunAs
Group.
https://fedorahosted.org/freeipa/ticket/1657
2011-08-23 00:21:27 -04:00
Jr Aquino
9821160d89
Correct sudo runasuser and runasgroup attributes in schema
...
https://fedorahosted.org/freeipa/ticket/1309
2011-07-19 08:06:41 -04:00
Jr Aquino
78c3abd6ba
Correct behavior for sudorunasgroup vs sudorunasuser
...
https://fedorahosted.org/freeipa/ticket/1309
2011-07-19 08:06:21 -04:00
Jr Aquino
9869b0971d
35 remove escapes from the cvs parser in ipaserver/install/ldapupdate https://fedorahosted.org/freeipa/ticket/1472
2011-07-19 09:44:04 +02:00
Jr Aquino
0359e2a043
Return correct "RunAs External Group" when removing members
...
If you used sudorule-remove-runasgroup to remove a member that member
still appeared in the command output when --all was included (it isn't a
default attribute). This was due to post-processing to evaluate external
users/groups, the entry was actually updated properly.
https://fedorahosted.org/freeipa/ticket/1348
2011-07-18 07:32:53 -04:00
Jr Aquino
d49bf3871b
oneliner correct typo in ipasudorunas_group
...
https://fedorahosted.org/freeipa/ticket/1326
2011-06-26 20:30:54 -04:00
Jr Aquino
ed7a3e005a
Don't add empty tuple to entry_attrs['externalhost']
...
https://fedorahosted.org/freeipa/ticket/1339
2011-06-16 19:22:15 -04:00
Jr Aquino
44cdf8ef54
Raise DuplicateEntry Error when adding a duplicate sudo option
...
https://fedorahosted.org/freeipa/ticket/1276
https://fedorahosted.org/freeipa/ticket/1277
https://fedorahosted.org/freeipa/ticket/1308
Added new Exception: AttrValueNotFound
Fixed XML Test for Sudorule remove_option
1276 (Raise AttrValueNotFound when trying to remove a non-existent option from Sudo rule)
1277 (Raise DuplicateEntry Error when adding a duplicate sudo option)
1308 (Make sudooption a required option for sudorule_remove_option)
2011-06-16 19:21:07 -04:00
Jr Aquino
6e5885d109
Display remaining external hosts when removing from sudorule
...
https://fedorahosted.org/freeipa/ticket/1269
https://fedorahosted.org/freeipa/ticket/1270
2011-06-14 00:04:08 -04:00
Jr Aquino
d7c60205a6
Add sudorule and hbacrule to memberof and indirectmemberof attributes
...
Add Add tests for users, groups, hosts and hostgroups to verify membership
Update API to version 2.3
https://fedorahosted.org/freeipa/ticket/1170
2011-06-06 13:14:38 -04:00
Jr Aquino
5a4f77ac14
28 One Liner: Typo in host_nis_groups has been creating 2 CN's
2011-05-25 16:36:25 -04:00
Jr Aquino
756d61724e
Return copy of config from ipa_get_config()
...
It was discovered that using the batch plugin it was possible to
store duplicate data in parts of the ipa_config during iterations.
This was causing a cascading exec failures if any one of the batch
executions failed.
https://fedorahosted.org/freeipa/ticket/1220
2011-05-13 13:09:24 -04:00
Jr Aquino
23781c080b
Delete the sudoers entry when disabling Schema Compat
...
https://fedorahosted.org/freeipa/ticket/1160
2011-04-25 14:35:34 -04:00
Jr Aquino
cc0e6680b9
Optimize and dynamically verify group membership
...
Rather than doing full searches for members read each member individually
to determine if it is direct or indirect.
Also add a fail-safe when calculating indirect membership so removing
a member will log enough information for debugging (ticket 1133).
https://fedorahosted.org/freeipa/ticket/1139
https://fedorahosted.org/freeipa/ticket/1133
2011-04-22 14:15:16 -04:00
Jr Aquino
25d301ef71
Add memberHost and memberUser to default indexes
...
https://fedorahosted.org/freeipa/ticket/1138
2011-04-08 11:00:24 -04:00
Jr Aquino
463d7d2fe8
Escape LDAP characters in member and memberof searches
...
https://fedorahosted.org/freeipa/ticket/1140
2011-03-31 12:52:08 -04:00
Jr Aquino
1770750b8a
Create default disabled sudo bind user
...
Read access is denied to the sudo container for unauthenticated users.
This shared user can be used to provide authenticated access to the
sudo information.
https://fedorahosted.org/freeipa/ticket/998
2011-02-23 15:32:24 -05:00
Jr Aquino
32e4914584
18 Use TLS for ipadiscovery during ipa-client-install https://fedorahosted.org/freeipa/ticket/974
2011-02-21 16:09:37 -05:00
Jr Aquino
478186e485
Cleanup for netgroup search https://fedorahosted.org/freeipa/ticket/963
2011-02-18 10:32:35 -05:00
Jr Aquino
d781dbd045
17-2 Managed netgroups should be invisible https://fedorahosted.org/freeipa/ticket/963
2011-02-16 17:52:21 -05:00
Jr Aquino
72e315c936
Bugfix for ipa-client-install echo's password in cleartext to stdout https://fedorahosted.org/freeipa/ticket/959
2011-02-14 15:43:18 -05:00
Jr Aquino
7b04b2240b
block anonymous access to sudo info https://fedorahosted.org/freeipa/ticket/865
2011-01-27 22:22:38 -05:00
Jr Aquino
5a0c9371cb
Bugfix for sudo compat cmdcat and deny commands https://fedorahosted.org/freeipa/ticket/742
2011-01-12 11:43:05 -05:00
Jr Aquino
1ea31a0cff
fix sudorule runas user/groups https://fedorahosted.org/freeipa/ticket/570
2011-01-12 11:40:47 -05:00
Jr Aquino
cbe02578db
fixed typo for description usage example https://fedorahosted.org/freeipa/ticket/704
2011-01-06 11:13:23 -05:00
Jr Aquino
9d9e15456b
netgroups created by hostgroups lacked info https://fedorahosted.org/freeipa/ticket/653
2011-01-03 10:22:55 -05:00
Jr Aquino
07e55f44b2
dbe instead of lde One line bug fix for compat and nis tools
2010-12-22 11:05:34 -05:00
Jr Aquino
e5e649988e
Fix to man page for ipa-compat-manage There was a typo for the manpage, this is a one liner to fix.
2010-12-21 17:51:41 -05:00
Jr Aquino
fc8f7f9da8
SUDO plugin support for external hosts and users https://fedorahosted.org/freeipa/ticket/570
2010-12-21 12:29:46 -05:00
Jr Aquino
ced639eb99
tests for sudo run as user or group https://fedorahosted.org/freeipa/ticket/570
2010-12-13 17:56:13 -05:00
Jr Aquino
b23b3911d2
sudo run as user or group https://fedorahosted.org/freeipa/ticket/570
2010-12-13 17:56:13 -05:00
Jr Aquino
13139f2fd6
managed entry hostgroup netgroup support https://fedorahosted.org/freeipa/ticket/543
2010-12-13 17:56:12 -05:00
Jr Aquino
751ee81771
Enable/Disable SudoRule https://fedorahosted.org/freeipa/ticket/570
2010-12-08 11:32:55 -05:00
Jr Aquino
cdf360151b
Adding user/host category and ipaenabledflag https://fedorahosted.org/freeipa/ticket/570 This patch Addresses items: 1. The UI needs a rule status with values active & inactive. The CLI doesn't have this attribute. HBAC has ipaenabledflag attribute which can be managed using hbac-enable/disable operations. 2. The UI needs a user category for the "Who" section. The CLI doesn't have this attribute. HBAC has usercategory attribute which can be managed using hbac-add/mod operations. 3. The UI needs a host category for the "Access this host" section. The CLI doesn't have this attribute. HBAC has hostcategory attribute which can be managed using hbac-add/mod operations.
2010-12-08 10:30:02 -05:00
Jr Aquino
c99fda0d1e
Added fixes to adjust for sudocmd attribute for sudocmds. Added fix for sudorule to allow for cmdCategory all Added fixes for xmlrpc tests to reflect sudocmd changes.
2010-11-03 10:23:40 -04:00
Jr Aquino
bfd2e383dc
Added modifications to the sudorule plugin to reflect the schema update.
2010-10-05 21:37:59 -04:00
Jr Aquino
af48654cbc
Add plugins for Sudo Commands, Command Groups and Rules
2010-09-27 22:38:06 -04:00