freeipa/install
Martin Kosek 4760c15cb2 Add automount map/key update permissions
Add missing permissions that can be used to delegate write access
to existing automount maps or keys.

Since automount key RDN has been changed in the past from "automountkey"
to "description" and there can be LDAP entries with both RDNs,
structure of relevant ACI need to be changed to different scheme. Now,
it rather targets a DN of parent automount map object and uses
targetfilter to limit the target to automount key objects only.

https://fedorahosted.org/freeipa/ticket/2687
2012-07-10 20:41:14 -04:00
..
conf Fix compatibility with Fedora 18. 2012-07-02 15:20:13 +02:00
html Fixed inconsistent image names. 2011-10-27 14:05:12 +00:00
migration Forms based authentication UI 2012-03-02 11:04:33 +01:00
po validate i18n strings when running "make lint" 2012-04-26 13:53:37 +02:00
restart_scripts Configure certmonger to execute restart scripts on renewal. 2012-04-10 01:08:41 -04:00
share Add automount map/key update permissions 2012-07-10 20:41:14 -04:00
tools Fix wrong option name in ipa-managed-entries man page 2012-07-11 15:33:12 +02:00
ui Add and remove dns per-domain permission in Web UI 2012-07-11 16:33:10 +02:00
updates Add automount map/key update permissions 2012-07-10 20:41:14 -04:00
configure.ac Configure certmonger to execute restart scripts on renewal. 2012-04-10 01:08:41 -04:00
Makefile.am Add sysupgrade state file 2012-06-10 21:23:10 -04:00
README.schema Add some basic rules for adding new schema 2010-08-27 13:40:37 -04:00

Ground rules on adding new schema

Brand new schema, particularly when written specifically for IPA, should be
added in share/*.ldif. Any new files need to be explicitly loaded in
ipaserver/install/dsinstance.py. These simply get copied directly into
the new instance schema directory.

Existing schema (e.g. in an LDAP draft) may either be added as a separate
ldif in share or as an update in the updates directory. The advantage of
adding the schema as an update is if 389-ds ever adds the schema then the
installation won't fail due to existing schema failing to load during
bootstrap.

If the new schema requires a new container then this should be added
to install/bootstrap-template.ldif.