RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Bug 1211595 - [RFE] add admins group, ipa masters hostgroup, ssh HBAC rule
Summary: [RFE] add admins group, ipa masters hostgroup, ssh HBAC rule
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: ipa
Version: 7.1
Hardware: Unspecified
OS: Unspecified
medium
unspecified
Target Milestone: rc
: ---
Assignee: IPA Maintainers
QA Contact: Namita Soman
Marc Muehlfeld
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-04-14 12:08 UTC by Petr Vobornik
Modified: 2016-11-04 05:45 UTC (History)
6 users (show)

Fixed In Version: ipa-4.4.0-1.el7
Doc Type: Enhancement
Doc Text:
IdM now enables the `admin` group and `ipaservers` host group Identity Management (IdM) now introduces two new groups: * User group `admins` - Members have full administrative permissions in IdM. * Host group `ipaservers` - Hosts in this group can be promoted to a replica by users without full administrative permissions. All IdM servers are members of this group.
Clone Of:
Environment:
Last Closed: 2016-11-04 05:45:18 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2016:2404 0 normal SHIPPED_LIVE ipa bug fix and enhancement update 2016-11-03 13:56:18 UTC

Description Petr Vobornik 2015-04-14 12:08:19 UTC
This bug is created as a clone of upstream ticket:
https://fedorahosted.org/freeipa/ticket/3416

We want users in the admins group to always be able to log into the IPA masters.

We should create a new hostgroup that contains all of the IPA masters in it. This hostgroup would be created on new installs and updated at the same time that cn=masters is updated (so via replication changes and when new masters are added).

A new HBAC rule for the ssh service will be added that allows users in the admins group to machines in the IPA masters hostgroup.

We will not prevent additional hosts to be added to the hostgroup.

A task will be needed to handle upgrades so that any missing IPA masters can be added.

Comment 2 Petr Vobornik 2015-12-11 11:53:12 UTC
The required functionality for replica promotion was implemented upstream in

* a8d7ce5cf1ccd6c8a81fa5b4569afa3aa3c2882d aci: add IPA servers host group 'ipaservers'
* 7b9a97383ce4090d30e624fc8b7263d6c5f1b823 aci: replace per-server ACIs with 
ipaserver-based ACIs 
* 8f36a5bd68140fdd338d9c738977a6c67fdfdf08 replica install: add ipaservers if it does not exist 

HBAC rule was not implemented and is not needed for replica promotion.

Comment 3 Mike McCune 2016-03-28 22:43:24 UTC
This bug was accidentally moved from POST to MODIFIED via an error in automation, please see mmccune with any questions

Comment 4 Petr Vobornik 2016-07-01 12:22:39 UTC
copying comment: https://fedorahosted.org/freeipa/ticket/3416#comment:14

admins user group and ipaservers host group exist now(4.3). Therefore moving this ticket to 4.3 as fixed.

For the hbac rule part, if anybody wants it, please open a new RFE ticket.

Comment 5 Petr Vobornik 2016-07-13 14:55:35 UTC
this bz was part of rebase

Comment 7 Kaleem 2016-08-29 10:21:16 UTC
Please provide steps to verify this.

Comment 8 Nikhil Dehadrai 2016-09-19 15:15:03 UTC
IPA-server version: ipa-server-4.4.0-12.el7.x86_64

Tested the bug on the basis of following steps:
1. Noticed that new user group 'admin' is now available for latest version of IPA server.
2. Noticed that new hostgroup "ipaservers" is now available for latest version of IPA server.
3. Noticed that Master/ replica automatically become part of it after upgrade or on fresh install of ipa-server/replica.
4. Noticed that new users can be manually added to 'admins' group.
5. Noticed that new host can be manually added to 'ipaservers' group.
6. As for the hbacrule observation (HBAC rule is not implemented) in above comment#2 and #4, it will be handled separately.

Thus on the basis of above observations, marking the status of bug to "VERIFIED".

Comment 9 Martin Bašti 2016-09-26 11:51:58 UTC
Bug is verified needinfo is not needed, I was contacted personally.

Comment 14 errata-xmlrpc 2016-11-04 05:45:18 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-2404.html


Note You need to log in before you can comment on or make changes to this bug.