summaryrefslogtreecommitdiffstats
path: root/zarb-ml/mageia-sysadm/attachments/20101109/431b95e6/attachment-0001.html
diff options
context:
space:
mode:
Diffstat (limited to 'zarb-ml/mageia-sysadm/attachments/20101109/431b95e6/attachment-0001.html')
-rw-r--r--zarb-ml/mageia-sysadm/attachments/20101109/431b95e6/attachment-0001.html172
1 files changed, 172 insertions, 0 deletions
diff --git a/zarb-ml/mageia-sysadm/attachments/20101109/431b95e6/attachment-0001.html b/zarb-ml/mageia-sysadm/attachments/20101109/431b95e6/attachment-0001.html
new file mode 100644
index 000000000..cfffeaf1d
--- /dev/null
+++ b/zarb-ml/mageia-sysadm/attachments/20101109/431b95e6/attachment-0001.html
@@ -0,0 +1,172 @@
+<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
+"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
+<html xmlns="http://www.w3.org/1999/xhtml">
+<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
+<title>[212] Close more anon access, and open up read access to some inetOrgPerson attrs to users</title>
+</head>
+<body>
+
+<style type="text/css"><!--
+#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
+#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
+#msg dt:after { content:':';}
+#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; }
+#msg dl a { font-weight: bold}
+#msg dl a:link { color:#fc3; }
+#msg dl a:active { color:#ff0; }
+#msg dl a:visited { color:#cc6; }
+h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
+#msg pre { overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
+#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
+#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
+#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
+#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
+#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
+#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
+#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; }
+#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; }
+#logmsg pre { background: #eee; padding: 1em; }
+#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
+#logmsg dl { margin: 0; }
+#logmsg dt { font-weight: bold; }
+#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
+#logmsg dd:before { content:'\00bb';}
+#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
+#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
+#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
+#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
+#logmsg table th.Corner { text-align: left; }
+#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
+#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
+#patch { width: 100%; }
+--></style>
+<div id="msg">
+<dl class="meta">
+<dt>Revision</dt> <dd>212</dd>
+<dt>Author</dt> <dd>buchan</dd>
+<dt>Date</dt> <dd>2010-11-09 15:25:10 +0100 (Tue, 09 Nov 2010)</dd>
+</dl>
+
+<h3>Log Message</h3>
+<pre>Close more anon access, and open up read access to some inetOrgPerson attrs to users</pre>
+
+<h3>Modified Paths</h3>
+<ul>
+<li><a href="#puppetmodulesopenldaptemplatesmandrivaditaccessconf">puppet/modules/openldap/templates/mandriva-dit-access.conf</a></li>
+</ul>
+
+</div>
+<div id="patch"><pre>
+<a id="puppetmodulesopenldaptemplatesmandrivaditaccessconf">Modified: puppet/modules/openldap/templates/mandriva-dit-access.conf</a>
+===================================================================
+--- puppet/modules/openldap/templates/mandriva-dit-access.conf 2010-11-09 02:21:57 UTC (rev 211)
++++ puppet/modules/openldap/templates/mandriva-dit-access.conf 2010-11-09 14:25:10 UTC (rev 212)
+@@ -33,7 +33,7 @@
+ attrs=shadowLastChange
+ by self write
+ by group.exact=&quot;cn=Account Admins,ou=System Groups,dc=mageia,dc=org&quot; write
+- by * read
++ by users read
+ access to dn.subtree=&quot;dc=mageia,dc=org&quot;
+ attrs=userPassword
+ by group.exact=&quot;cn=Account Admins,ou=System Groups,dc=mageia,dc=org&quot; write
+@@ -53,7 +53,7 @@
+ # password policies
+ access to dn.subtree=&quot;ou=Password Policies,dc=mageia,dc=org&quot;
+ by group.exact=&quot;cn=Account Admins,ou=System Groups,dc=mageia,dc=org&quot; write
+- by * read
++ by users read
+
+ # samba password attributes
+ # by self not strictly necessary, because samba uses its own admin user to
+@@ -77,16 +77,18 @@
+ access to dn.subtree=&quot;dc=mageia,dc=org&quot;
+ attrs=pwdReset,pwdAccountLockedTime
+ by group.exact=&quot;cn=Account Admins,ou=System Groups,dc=mageia,dc=org&quot; write
+- by * read
++ by self read
+
+ # group owner can add/remove/edit members to groups
+ access to dn.regex=&quot;^cn=[^,]+,ou=(System Groups|Group),dc=mageia,dc=org$&quot;
+ attrs=member
+ by dnattr=owner write
++ by group.exact=&quot;cn=Account Admins,ou=System Groups,dc=mageia,dc=org&quot; write
+ by users +sx
+
+ access to dn.regex=&quot;^cn=[^,]+,ou=(System Groups|Group),dc=mageia,dc=org$&quot;
+ attrs=cn,description,objectClass,gidNumber
++ by group.exact=&quot;cn=Account Admins,ou=System Groups,dc=mageia,dc=org&quot; write
+ by users read
+
+ # registration - allow registrar group to create basic unprivileged accounts
+@@ -106,7 +108,7 @@
+ access to dn.subtree=&quot;ou=People,dc=mageia,dc=org&quot;
+ attrs=carLicense,homePhone,homePostalAddress,mobile,pager,telephoneNumber,mail,preferredLanguage
+ by self write
+- by users +sx
++ by users read
+
+ # create new accounts
+ access to dn.regex=&quot;^([^,]+,)?ou=(People|Group|Hosts),dc=mageia,dc=org$&quot;
+@@ -122,21 +124,21 @@
+ access to dn.regex=&quot;^(sambaDomainName=[^,]+,)?dc=mageia,dc=org$&quot;
+ attrs=children,entry,@sambaDomain,@sambaUnixIdPool
+ by group.exact=&quot;cn=Account Admins,ou=System Groups,dc=mageia,dc=org&quot; write
+- by * read
++ by users read
+
+ # samba ID mapping
+ access to dn.regex=&quot;^(sambaSID=[^,]+,)?ou=Idmap,dc=mageia,dc=org$&quot;
+ attrs=children,entry,@sambaIdmapEntry
+ by group.exact=&quot;cn=Account Admins,ou=System Groups,dc=mageia,dc=org&quot; write
+ by group.exact=&quot;cn=IDMAP Admins,ou=System Groups,dc=mageia,dc=org&quot; write
+- by * read
++ by users read
+
+ # global address book
+ # XXX - which class(es) to use?
+ access to dn.regex=&quot;^(.*,)?ou=Address Book,dc=mageia,dc=org&quot;
+ attrs=children,entry,@inetOrgPerson,@evolutionPerson,@evolutionPersonList
+ by group.exact=&quot;cn=Address Book Admins,ou=System Groups,dc=mageia,dc=org&quot; write
+- by * read
++ by users read
+
+ # dhcp entries
+ # XXX - open up read access to anybody?
+@@ -150,13 +152,13 @@
+ access to dn.regex=&quot;^([^,]+,)?ou=sudoers,dc=mageia,dc=org$&quot;
+ attrs=children,entry,@sudoRole
+ by group.exact=&quot;cn=Sudo Admins,ou=System Groups,dc=mageia,dc=org&quot; write
+- by * read
++ by users read
+
+ # dns
+ access to dn=&quot;ou=dns,dc=mageia,dc=org&quot;
+ attrs=entry,@extensibleObject
+ by group.exact=&quot;cn=DNS Admins,ou=System Groups,dc=mageia,dc=org&quot; write
+- by * read
++ by users read
+ access to dn.sub=&quot;ou=dns,dc=mageia,dc=org&quot;
+ attrs=children,entry,@dNSZone
+ by group.exact=&quot;cn=DNS Admins,ou=System Groups,dc=mageia,dc=org&quot; write
+@@ -169,7 +171,7 @@
+ access to dn.one=&quot;ou=People,dc=mageia,dc=org&quot;
+ attrs=@inetLocalMailRecipient,mail
+ by group.exact=&quot;cn=MTA Admins,ou=System Groups,dc=mageia,dc=org&quot; write
+- by * read
++ by users read
+
+ # KDE Configuration
+ access to dn.sub=&quot;ou=KDEConfig,dc=mageia,dc=org&quot;
+@@ -178,5 +180,5 @@
+
+ # last one
+ access to dn.subtree=&quot;dc=mageia,dc=org&quot; attrs=entry,uid,cn
+- by * read
++ by users read
+
+
+</pre></div>
+
+</body>
+</html> \ No newline at end of file