"Fossies" - the Fresh Open Source Software Archive

Member "freeipa-4.8.8/install/updates/40-replication.update" (15 Jun 2020, 2240 Bytes) of package /linux/misc/freeipa-4.8.8.tar.gz:


As a special service "Fossies" has tried to format the requested text file into HTML format (style: standard) with prefixed line numbers. Alternatively you can here view or download the uninterpreted source code file. See also the last Fossies "Diffs" side-by-side code changes report for "40-replication.update": 4.8.6_vs_4.8.7.

    1 # Let a delegated user put the database into read-only mode when deleting
    2 # an agreement.
    3 dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config
    4 remove:aci: (targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,$SUFFIX";)
    5 add:aci: (targetattr = "nsslapd-readonly")(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,$SUFFIX";)
    6 
    7 # Add rules to manage DNA ranges
    8 dn: cn=Modify DNA Range,cn=permissions,cn=pbac,$SUFFIX
    9 default:objectClass: top
   10 default:objectClass: groupofnames
   11 default:objectClass: ipapermission
   12 default:cn: Modify DNA Range
   13 default:ipapermissiontype: SYSTEM
   14 default:member: cn=Replication Administrators,cn=privileges,cn=pbac,$SUFFIX
   15 
   16 dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config
   17 remove:aci: (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,$SUFFIX";)
   18 add:aci: (targetattr = "dnaNextRange || dnaNextValue || dnaMaxValue")(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,$SUFFIX";)
   19 
   20 dn: cn=Read DNA Range,cn=permissions,cn=pbac,$SUFFIX
   21 default:objectClass: top
   22 default:objectClass: groupofnames
   23 default:objectClass: ipapermission
   24 default:cn: Read DNA Range
   25 default:ipapermissiontype: SYSTEM
   26 default:member: cn=Replication Administrators,cn=privileges,cn=pbac,$SUFFIX
   27 
   28 dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config
   29 remove:aci: (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue  || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,$SUFFIX";)
   30 add:aci: (targetattr = "cn || dnaMaxValue || dnaNextRange || dnaNextValue  || dnaThreshold || dnaType || objectclass")(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,$SUFFIX";)