summaryrefslogtreecommitdiff
path: root/src/providers/ipa/ipa_hbac_private.h
AgeCommit message (Collapse)AuthorFilesLines
2012-11-20LDAP: Only convert direct parents' ghost attribute to memberJakub Hrozek1-1/+0
https://fedorahosted.org/sssd/ticket/1612 This patch changes the handling of ghost attributes when saving the actual user entry. Instead of always linking all groups that contained the ghost attribute with the new user entry, the original member attributes are now saved in the group object and the user entry is only linked with its direct parents. As the member attribute is compared against the originalDN of the user, if either the originalDN or the originalMember attributes are missing, the user object is linked with all the groups as a fallback. The original member attributes are only saved if the LDAP schema supports nesting.
2012-02-24IPA hosts refactoringJan Zeleny1-6/+0
2012-02-06Separate the host-retrieval code from IPA HBAC to common IPA codeJan Zeleny1-19/+0
2012-02-06Implemented support for multiple search bases in HBAC rules and servicesJan Zeleny1-17/+1
2012-01-14Support multiple search bases in HBACJan Zeleny1-1/+1
2011-11-29Add ipa_hbac_support_srchost option to IPA providerJan Zeleny1-0/+3
don't fetch all host groups if this option is false https://fedorahosted.org/sssd/ticket/1078
2011-11-22Cleanup: Remove unused parametersJakub Hrozek1-8/+0
2011-10-14HBAC: Use originalMember for identifying hostgroupsStephen Gallagher1-0/+5
2011-10-14HBAC: Use originalMember for identifying servicegroupsStephen Gallagher1-0/+5
2011-07-08Add helper functions for looking up HBAC rule componentsStephen Gallagher1-0/+194