freeipa/install/updates/30-hbacsvc.update
Dmitri Pal 52af18ec03 Enabling SUDO support
* Adding a new SUDO schema file
* Adding this new file to the list of targets in make file
* Create SUDO container for sudo rules
* Add default sudo services to HBAC services
* Add default SUDO HBAC service group with two services sudo & sudo-i
* Installing schema

No SUDO rules are created by default by this patch.
2010-09-16 11:31:27 -04:00

61 lines
1.7 KiB
Plaintext

dn: cn=sshd,cn=hbacservices,cn=accounts,$SUFFIX
default:objectclass: ipahbacservice
default:objectclass: ipaobject
default:cn: sshd
default:description: sshd
default:ipauniqueid:$UUID
dn: cn=ftp,cn=hbacservices,cn=accounts,$SUFFIX
default:objectclass: ipahbacservice
default:objectclass: ipaobject
default:cn: ftp
default:description: ftp
default:ipauniqueid:$UUID
dn: cn=su,cn=hbacservices,cn=accounts,$SUFFIX
default:objectclass: ipahbacservice
default:objectclass: ipaobject
default:cn: su
default:description: su
default:ipauniqueid:$UUID
dn: cn=login,cn=hbacservices,cn=accounts,$SUFFIX
default:objectclass: ipahbacservice
default:objectclass: ipaobject
default:cn: login
default:description: login
default:ipauniqueid:$UUID
dn: cn=su-l,cn=hbacservices,cn=accounts,$SUFFIX
default:objectclass: ipahbacservice
default:objectclass: ipaobject
default:cn: su-l
default:description: su with login shell
default:ipauniqueid:$UUID
dn: cn=sudo,cn=hbacservices,cn=accounts,$SUFFIX
default:objectclass: ipahbacservice
default:objectclass: ipaobject
default:cn: sudo
default:description: sudo
default:ipauniqueid:$UUID
dn: cn=sudo-i,cn=hbacservices,cn=accounts,$SUFFIX
default:objectclass: ipahbacservice
default:objectclass: ipaobject
default:cn: sudo-i
default:description: sudo-i
default:ipauniqueid:$UUID
dn: cn=SUDO,cn=hbacservicegroups,cn=accounts,$SUFFIX
default:objectClass: ipaobject
default:objectClass: ipahbacservicegroup
default:objectClass: nestedGroup
default:objectClass: groupOfNames
default:objectClass: top
default:cn: SUDO
default:ipauniqueid:$UUID
default:description: Default group of SUDO related services
default:member: cn=sudo,cn=hbacservices,cn=accounts,$SUFFIX
default:member: cn=sudo-i,cn=hbacservices,cn=accounts,$SUFFIX