freeipa/ipaserver
Petr Viktorin 63becae88c Set user addressbook/IPA attribute read ACI to anonymous on upgrades from 3.x
When upgrading from an "old" IPA, or installing the first "new" replica,
we need to keep allowing anonymous access to many user attributes.

Add an optional 'fixup_function' to the managed permission templates,
and use it to set the bind rule type to 'anonymous' when installing
(or upgrading to) the first "new" master.

This assumes that the anonymous read ACI will be removed in a "new" IPA.

Part of the work for: https://fedorahosted.org/freeipa/ticket/3566

Reviewed-By: Martin Kosek <mkosek@redhat.com>
2014-05-26 12:12:35 +02:00
..
advise ipa tool: Print the name of the server we are connecting to with -v 2014-02-05 15:35:36 +01:00
install Set user addressbook/IPA attribute read ACI to anonymous on upgrades from 3.x 2014-05-26 12:12:35 +02:00
plugins Always use real entry DNs for memberOf in ldap2. 2014-02-24 14:30:23 +01:00
__init__.py Change FreeIPA license to GPLv3+ 2010-12-20 17:19:53 -05:00
dcerpc.py Trust add datetime fix 2014-05-06 19:14:45 +03:00
rpcserver.py Support API version-specific RPC marshalling. 2014-04-18 14:59:20 +02:00