Hide Forgot
Description of problem: example: such command : ipa selfservice-mod "edit address" --attrs="nosuchattr" will delete selfservice permission "edit address" from ipa server Version-Release number of selected component (if applicable): [yi@i386a(101) ~] rpm -qi ipa-server Name : ipa-server Relocations: (not relocatable) Version : 2.1.3 Vendor: Red Hat, Inc. Release : 2.el6 Build Date: Tue 18 Oct 2011 11:12:34 AM PDT Install Date: Thu 20 Oct 2011 10:39:05 AM PDT Build Host: x86-002.build.bos.redhat.com Group : System Environment/Base Source RPM: ipa-2.1.3-2.el6.src.rpm Size : 3355311 License: GPLv3+ Signature : (none) Packager : Red Hat, Inc. <http://bugzilla.redhat.com/bugzilla> URL : http://www.freeipa.org/ Summary : The IPA authentication server Description : IPA is an integrated solution to provide centrally managed Identity (machine, user, virtual machines, groups, authentication credentials), Policy (configuration settings, access control information) and Audit (events, logs, analysis thereof). If you are installing an IPA server you need to install this package (in other words, most people should NOT install this package). How reproducible: always Steps to Reproduce: 1. install ipa server 2. create selfservice permission [yi@i386a(101) ~] ipa selfservice-add "edit address" --permission=write,read --attrs=l -------------------------------- Added selfservice "edit address" -------------------------------- Self-service name: edit address Permissions: write, read Attributes: l 3. modify this permission by providing wrong attr value [yi@i386a(101) ~] ipa selfservice-mod "edit address" --attrs="nosuchattr" ipa: ERROR: targetattr "nosuchattr" does not exist in schema. Please add attributeTypes "nosuchattr" to schema if necessary. ACL Syntax Error(-5):(targetattr = \22nosuchattr\22)(version 3.0;acl \22selfservice:edit address\22;allow (write,read) userdn = \22ldap:///self\22;): Invalid syntax. -- the return message is correct, but the permission is disappeared from ipa server, [yi@i386a(101) ~] ipa selfservice-find "edit address" ---------------------- 0 selfservices matched ---------------------- ---------------------------- Number of entries returned 0 ---------------------------- Actual results: Expected results: Additional info: no error msg found in /var/log/httpd/error_log
Upstream ticket: https://fedorahosted.org/freeipa/ticket/2014
Fixed upstream: master: https://fedorahosted.org/freeipa/changeset/d50618f6bd032b59a1893f7eb23e47616efab8fe ipa-2-2: https://fedorahosted.org/freeipa/changeset/fcbff4b102c47d5c8543f031baf96f9f4deb2c4e
Verified. Version :: ipa-server-2.2.0-4.el6.x86_64 Automated Test Results :: :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: [ LOG ] :: selfservice_bz_747741 ipa selfservice-mod provide wrong attr for --attrs delete a selfservice permission :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: [ LOG ] :: BZ Test Running: ipa selfservice-mod selfservice_bz_747741 --attrs=badattrs > /tmp/tmp.V5BS5xp3mS/selfservice_bz_747741.10021.out 2>&1 :: [ LOG ] :: Duration: 12s :: [ LOG ] :: Assertions: 0 good, 0 bad :: [ PASS ] :: RESULT: selfservice_bz_747741 ipa selfservice-mod provide wrong attr for --attrs delete a selfservice permission Manual Test Results :: [root@hp-xw6600-01 ipa-selfservice]# ipa selfservice-add bz747741 --attrs=l ---------------------------- Added selfservice "bz747741" ---------------------------- Self-service name: bz747741 Permissions: write Attributes: l [root@hp-xw6600-01 ipa-selfservice]# ipa selfservice-mod bz747741 --attrs=badattr ipa: ERROR: targetattr "badattr" does not exist in schema. Please add attributeTypes "badattr" to schema if necessary. ACL Syntax Error(-5):(targetattr = \22badattr\22)(version 3.0;acl \22selfservice:bz747741\22;allow (write) userdn = \22ldap:///self\22;): Invalid syntax. [root@hp-xw6600-01 ipa-selfservice]# ipa selfservice-show bz747741 Self-service name: bz747741 Permissions: write Attributes: l [root@hp-xw6600-01 ipa-selfservice]# ipa selfservice-find bz747741--------------------- 1 selfservice matched --------------------- Self-service name: bz747741 Permissions: write Attributes: l ---------------------------- Number of entries returned 1 ----------------------------
Technical note added. If any revisions are required, please edit the "Technical Notes" field accordingly. All revisions will be proofread by the Engineering Content Services team. New Contents: No documentation needed.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2012-0819.html