Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1211595 - [RFE] add admins group, ipa masters hostgroup, ssh HBAC rule
[RFE] add admins group, ipa masters hostgroup, ssh HBAC rule
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: ipa (Show other bugs)
7.1
Unspecified Unspecified
medium Severity unspecified
: rc
: ---
Assigned To: IPA Maintainers
Namita Soman
Marc Muehlfeld
: FutureFeature
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2015-04-14 08:08 EDT by Petr Vobornik
Modified: 2016-11-04 01:45 EDT (History)
6 users (show)

See Also:
Fixed In Version: ipa-4.4.0-1.el7
Doc Type: Enhancement
Doc Text:
IdM now enables the `admin` group and `ipaservers` host group Identity Management (IdM) now introduces two new groups: * User group `admins` - Members have full administrative permissions in IdM. * Host group `ipaservers` - Hosts in this group can be promoted to a replica by users without full administrative permissions. All IdM servers are members of this group.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-11-04 01:45:18 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2016:2404 normal SHIPPED_LIVE ipa bug fix and enhancement update 2016-11-03 09:56:18 EDT

  None (edit)
Description Petr Vobornik 2015-04-14 08:08:19 EDT
This bug is created as a clone of upstream ticket:
https://fedorahosted.org/freeipa/ticket/3416

We want users in the admins group to always be able to log into the IPA masters.

We should create a new hostgroup that contains all of the IPA masters in it. This hostgroup would be created on new installs and updated at the same time that cn=masters is updated (so via replication changes and when new masters are added).

A new HBAC rule for the ssh service will be added that allows users in the admins group to machines in the IPA masters hostgroup.

We will not prevent additional hosts to be added to the hostgroup.

A task will be needed to handle upgrades so that any missing IPA masters can be added.
Comment 2 Petr Vobornik 2015-12-11 06:53:12 EST
The required functionality for replica promotion was implemented upstream in

* a8d7ce5cf1ccd6c8a81fa5b4569afa3aa3c2882d aci: add IPA servers host group 'ipaservers'
* 7b9a97383ce4090d30e624fc8b7263d6c5f1b823 aci: replace per-server ACIs with 
ipaserver-based ACIs 
* 8f36a5bd68140fdd338d9c738977a6c67fdfdf08 replica install: add ipaservers if it does not exist 

HBAC rule was not implemented and is not needed for replica promotion.
Comment 3 Mike McCune 2016-03-28 18:43:24 EDT
This bug was accidentally moved from POST to MODIFIED via an error in automation, please see mmccune@redhat.com with any questions
Comment 4 Petr Vobornik 2016-07-01 08:22:39 EDT
copying comment: https://fedorahosted.org/freeipa/ticket/3416#comment:14

admins user group and ipaservers host group exist now(4.3). Therefore moving this ticket to 4.3 as fixed.

For the hbac rule part, if anybody wants it, please open a new RFE ticket.
Comment 5 Petr Vobornik 2016-07-13 10:55:35 EDT
this bz was part of rebase
Comment 7 Kaleem 2016-08-29 06:21:16 EDT
Please provide steps to verify this.
Comment 8 Nikhil Dehadrai 2016-09-19 11:15:03 EDT
IPA-server version: ipa-server-4.4.0-12.el7.x86_64

Tested the bug on the basis of following steps:
1. Noticed that new user group 'admin' is now available for latest version of IPA server.
2. Noticed that new hostgroup "ipaservers" is now available for latest version of IPA server.
3. Noticed that Master/ replica automatically become part of it after upgrade or on fresh install of ipa-server/replica.
4. Noticed that new users can be manually added to 'admins' group.
5. Noticed that new host can be manually added to 'ipaservers' group.
6. As for the hbacrule observation (HBAC rule is not implemented) in above comment#2 and #4, it will be handled separately.

Thus on the basis of above observations, marking the status of bug to "VERIFIED".
Comment 9 Martin Bašti 2016-09-26 07:51:58 EDT
Bug is verified needinfo is not needed, I was contacted personally.
Comment 14 errata-xmlrpc 2016-11-04 01:45:18 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-2404.html

Note You need to log in before you can comment on or make changes to this bug.