mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2025-02-25 18:55:28 -06:00
* Adding a new SUDO schema file * Adding this new file to the list of targets in make file * Create SUDO container for sudo rules * Add default sudo services to HBAC services * Add default SUDO HBAC service group with two services sudo & sudo-i * Installing schema No SUDO rules are created by default by this patch.
61 lines
1.7 KiB
Plaintext
61 lines
1.7 KiB
Plaintext
dn: cn=sshd,cn=hbacservices,cn=accounts,$SUFFIX
|
|
default:objectclass: ipahbacservice
|
|
default:objectclass: ipaobject
|
|
default:cn: sshd
|
|
default:description: sshd
|
|
default:ipauniqueid:$UUID
|
|
|
|
dn: cn=ftp,cn=hbacservices,cn=accounts,$SUFFIX
|
|
default:objectclass: ipahbacservice
|
|
default:objectclass: ipaobject
|
|
default:cn: ftp
|
|
default:description: ftp
|
|
default:ipauniqueid:$UUID
|
|
|
|
dn: cn=su,cn=hbacservices,cn=accounts,$SUFFIX
|
|
default:objectclass: ipahbacservice
|
|
default:objectclass: ipaobject
|
|
default:cn: su
|
|
default:description: su
|
|
default:ipauniqueid:$UUID
|
|
|
|
dn: cn=login,cn=hbacservices,cn=accounts,$SUFFIX
|
|
default:objectclass: ipahbacservice
|
|
default:objectclass: ipaobject
|
|
default:cn: login
|
|
default:description: login
|
|
default:ipauniqueid:$UUID
|
|
|
|
dn: cn=su-l,cn=hbacservices,cn=accounts,$SUFFIX
|
|
default:objectclass: ipahbacservice
|
|
default:objectclass: ipaobject
|
|
default:cn: su-l
|
|
default:description: su with login shell
|
|
default:ipauniqueid:$UUID
|
|
|
|
dn: cn=sudo,cn=hbacservices,cn=accounts,$SUFFIX
|
|
default:objectclass: ipahbacservice
|
|
default:objectclass: ipaobject
|
|
default:cn: sudo
|
|
default:description: sudo
|
|
default:ipauniqueid:$UUID
|
|
|
|
dn: cn=sudo-i,cn=hbacservices,cn=accounts,$SUFFIX
|
|
default:objectclass: ipahbacservice
|
|
default:objectclass: ipaobject
|
|
default:cn: sudo-i
|
|
default:description: sudo-i
|
|
default:ipauniqueid:$UUID
|
|
|
|
dn: cn=SUDO,cn=hbacservicegroups,cn=accounts,$SUFFIX
|
|
default:objectClass: ipaobject
|
|
default:objectClass: ipahbacservicegroup
|
|
default:objectClass: nestedGroup
|
|
default:objectClass: groupOfNames
|
|
default:objectClass: top
|
|
default:cn: SUDO
|
|
default:ipauniqueid:$UUID
|
|
default:description: Default group of SUDO related services
|
|
default:member: cn=sudo,cn=hbacservices,cn=accounts,$SUFFIX
|
|
default:member: cn=sudo-i,cn=hbacservices,cn=accounts,$SUFFIX
|