mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2024-12-24 16:10:02 -06:00
f1f1b4e7f2
The password and modrdn plugins needed to be made transaction aware for the pre and post operations. Remove the reverse member hoop jumping. Just fetch the entry once and all the memberof data is there (plus objectclass). Fix some unit tests that are failing because we actually get the data now due to transactions. Add small bit of code in user plugin to retrieve the user again ala wait_for_attr but in the case of transactions we need do it only once. Deprecate wait_for_attr code. Add a memberof fixup task for roles. https://fedorahosted.org/freeipa/ticket/1263 https://fedorahosted.org/freeipa/ticket/1891 https://fedorahosted.org/freeipa/ticket/2056 https://fedorahosted.org/freeipa/ticket/3043 https://fedorahosted.org/freeipa/ticket/3191 https://fedorahosted.org/freeipa/ticket/3046
97 lines
5.0 KiB
Plaintext
97 lines
5.0 KiB
Plaintext
dn: cn=NIS Server, cn=plugins, cn=config
|
|
default:objectclass: top
|
|
default:objectclass: nsSlapdPlugin
|
|
default:objectclass: extensibleObject
|
|
default:cn: NIS Server
|
|
default:nsslapd-pluginpath: /usr/lib$LIBARCH/dirsrv/plugins/nisserver-plugin.so
|
|
default:nsslapd-plugininitfunc: nis_plugin_init
|
|
default:nsslapd-plugintype: object
|
|
default:nsslapd-pluginbetxn: on
|
|
default:nsslapd-pluginenabled: on
|
|
default:nsslapd-pluginid: nis-server
|
|
default:nsslapd-pluginversion: 0.10
|
|
default:nsslapd-pluginvendor: redhat.com
|
|
default:nsslapd-plugindescription: NIS Server Plugin
|
|
default:nis-tcp-wrappers-name: nis-server
|
|
|
|
dn: nis-domain=$DOMAIN+nis-map=passwd.byname, cn=NIS Server, cn=plugins, cn=config
|
|
default:objectclass: top
|
|
default:objectclass: extensibleObject
|
|
default:nis-domain: $DOMAIN
|
|
default:nis-map: passwd.byname
|
|
default:nis-base: cn=users, cn=accounts, $SUFFIX
|
|
default:nis-secure: no
|
|
|
|
dn: nis-domain=$DOMAIN+nis-map=passwd.byuid, cn=NIS Server, cn=plugins, cn=config
|
|
default:objectclass: top
|
|
default:objectclass: extensibleObject
|
|
default:nis-domain: $DOMAIN
|
|
default:nis-map: passwd.byuid
|
|
default:nis-base: cn=users, cn=accounts, $SUFFIX
|
|
default:nis-secure: no
|
|
|
|
dn: nis-domain=$DOMAIN+nis-map=group.byname, cn=NIS Server, cn=plugins, cn=config
|
|
default:objectclass: top
|
|
default:objectclass: extensibleObject
|
|
default:nis-domain: $DOMAIN
|
|
default:nis-map: group.byname
|
|
default:nis-base: cn=groups, cn=accounts, $SUFFIX
|
|
default:nis-secure: no
|
|
|
|
dn: nis-domain=$DOMAIN+nis-map=group.bygid, cn=NIS Server, cn=plugins, cn=config
|
|
default:objectclass: top
|
|
default:objectclass: extensibleObject
|
|
default:nis-domain: $DOMAIN
|
|
default:nis-map: group.bygid
|
|
default:nis-base: cn=groups, cn=accounts, $SUFFIX
|
|
default:nis-secure: no
|
|
|
|
dn: nis-domain=$DOMAIN+nis-map=netid.byname, cn=NIS Server, cn=plugins, cn=config
|
|
default:objectclass: top
|
|
default:objectclass: extensibleObject
|
|
default:nis-domain: $DOMAIN
|
|
default:nis-map: netid.byname
|
|
default:nis-base: cn=users, cn=accounts, $SUFFIX
|
|
default:nis-secure: no
|
|
|
|
# Note that the escapes in this entry can be quite confusing. The trick
|
|
# is that each level of nesting requires (2^n) - 1 escapes. So the
|
|
# first level is \", the second is \\\", the third is \\\\\\\", etc.
|
|
# (1, 3, 7, 15, more than that and you'll go insane)
|
|
|
|
# Note that this configuration mirrors the Schema Compat configuration for
|
|
# triples.
|
|
dn: nis-domain=$DOMAIN+nis-map=netgroup, cn=NIS Server, cn=plugins, cn=config
|
|
default:objectclass: top
|
|
default:objectclass: extensibleObject
|
|
default:nis-domain: $DOMAIN
|
|
default:nis-map: netgroup
|
|
default:nis-base: cn=ng, cn=alt, $SUFFIX
|
|
default:nis-filter: (objectClass=ipanisNetgroup)
|
|
default:nis-key-format: %{cn}
|
|
default:nis-value-format:%merge(" ","%deref_f(\"member\",\"(objectclass=ipanisNetgroup)\",\"cn\")","(%link(\"%ifeq(\\\"hostCategory\\\",\\\"all\\\",\\\"\\\",\\\"%collect(\\\\\\\"%{externalHost}\\\\\\\",\\\\\\\"%deref(\\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\\",\\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\\")\\\\\\\",\\\\\\\"%deref_r(\\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\\",\\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\\")\\\\\\\",\\\\\\\"%deref_r(\\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\\",\\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\\",\\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\\")\\\\\\\")\\\")\",\"%ifeq(\\\"hostCategory\\\",\\\"all\\\",\\\"\\\",\\\"-\\\")\",\",\",\"%ifeq(\\\"userCategory\\\",\\\"all\\\",\\\"\\\",\\\"%collect(\\\\\\\"%deref(\\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\\",\\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\\")\\\\\\\",\\\\\\\"%deref_r(\\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\\",\\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\\")\\\\\\\",\\\\\\\"%deref_r(\\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\\",\\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\\",\\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\\")\\\\\\\")\\\")\",\"%ifeq(\\\"userCategory\\\",\\\"all\\\",\\\"\\\",\\\"-\\\")\"),%{nisDomainName:-})")
|
|
default:nis-secure: no
|
|
|
|
dn: nis-domain=$DOMAIN+nis-map=ethers.byaddr, cn=NIS Server, cn=plugins, cn=config
|
|
default:objectclass: top
|
|
default:objectclass: extensibleObject
|
|
default:nis-domain: $DOMAIN
|
|
default:nis-map: ethers.byaddr
|
|
default:nis-base: cn=computers, cn=accounts, $SUFFIX
|
|
default:nis-filter: (&(macAddress=*)(fqdn=*)(objectClass=ipaHost))
|
|
default:nis-keys-format: %mregsub("%{macAddress} %{fqdn}","(..)[:\\\|-](..)[:\\\|-](..)[:\\\|-](..)[:\\\|-](..)[:\\\|-](..) (.*)","%1:%2:%3:%4:%5:%6")
|
|
default:nis-values-format: %mregsub("%{macAddress} %{fqdn}","(..)[:\\\|-](..)[:\\\|-](..)[:\\\|-](..)[:\\\|-](..)[:\\\|-](..) (.*)","%1:%2:%3:%4:%5:%6 %7")
|
|
default:nis-secure: no
|
|
|
|
dn: nis-domain=$DOMAIN+nis-map=ethers.byname, cn=NIS Server, cn=plugins, cn=config
|
|
default:objectclass: top
|
|
default:objectclass: extensibleObject
|
|
default:nis-domain: $DOMAIN
|
|
default:nis-map: ethers.byname
|
|
default:nis-base: cn=computers, cn=accounts, $SUFFIX
|
|
default:nis-filter: (&(macAddress=*)(fqdn=*)(objectClass=ipaHost))
|
|
default:nis-keys-format: %mregsub("%{macAddress} %{fqdn}","(..)[:\\\|-](..)[:\\\|-](..)[:\\\|-](..)[:\\\|-](..)[:\\\|-](..) (.*)","%7")
|
|
default:nis-values-format: %mregsub("%{macAddress} %{fqdn}","(..)[:\\\|-](..)[:\\\|-](..)[:\\\|-](..)[:\\\|-](..)[:\\\|-](..) (.*)","%1:%2:%3:%4:%5:%6 %7")
|
|
default:nis-secure: no
|
|
|