Bug 479176 - Admin access to configuration partition
Summary: Admin access to configuration partition
Keywords:
Status: CLOSED DEFERRED
Alias: None
Product: freeIPA
Classification: Retired
Component: ipa-server
Version: 2.0
Hardware: All
OS: Linux
low
medium
Target Milestone: v2 release
Assignee: Rob Crittenden
QA Contact: Ben Levenson
URL:
Whiteboard:
Depends On:
Blocks: 431020
TreeView+ depends on / blocked
 
Reported: 2009-01-07 19:02 UTC by Simo Sorce
Modified: 2015-01-21 12:31 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-01-21 12:31:12 UTC
Embargoed:


Attachments (Terms of Use)

Description Simo Sorce 2009-01-07 19:02:15 UTC
With IPA 1.x access to the configuration partition is permitted only for "cn=Directory Manager", for some common operations like creating replicas or in future configuration changes to some of the plugins (like DNA) it would be better to let admin have select write access and read access to parts on cn=config

We should add proper ACIs during v2 timeframe.

This will also allow better access to these configuration changes from the web ui.

Comment 2 Rob Crittenden 2010-09-14 16:47:50 UTC
The delete and manage agreements can be done but new agreements can not be created yet.

Comment 3 Dmitri Pal 2011-10-06 15:12:54 UTC
Upstream ticket:
https://fedorahosted.org/freeipa/ticket/1934

Comment 5 Martin Kosek 2015-01-21 12:31:12 UTC
Thank you taking your time and submitting this request for FreeIPA in Fedora. Unfortunately, this bug was not given a priority and was deferred both in Fedora and in the upstream FreeIPA project.

Given that we are unable to fulfill this request in following Fedora releases, I am closing the Bugzilla as DEFERRED. To request re-consideration of this decision please reopen this Bugzilla and provide additional technical details about its importance to you.

Note that you can still track this request or even contribute patches in the referred upstream Trac ticket.


Note You need to log in before you can comment on or make changes to this bug.