Re: [Freeipa-devel] [PATCHES] 0289-0302 Managed Read permissions

2013-11-04 Thread Martin Kosek
On 11/04/2013 04:48 PM, Petr Viktorin wrote: > On 10/21/2013 03:57 PM, Martin Kosek wrote: >> On 10/18/2013 04:28 PM, Petr Viktorin wrote: > [...] >>> >>> Alright, I'm crafting an updated design page with the above in mind. Here >>> are >>> the main differences. >>> >>> >>> New permissions won't (

Re: [Freeipa-devel] [PATCHES] 0289-0302 Managed Read permissions

2013-11-04 Thread Petr Viktorin
On 10/21/2013 03:57 PM, Martin Kosek wrote: On 10/18/2013 04:28 PM, Petr Viktorin wrote: [...] Alright, I'm crafting an updated design page with the above in mind. Here are the main differences. New permissions won't (necessarily) be in $SUFFIX, so old IPA servers will not be able to modify

Re: [Freeipa-devel] [PATCHES] 0289-0302 Managed Read permissions

2013-10-21 Thread Petr Viktorin
On 10/21/2013 03:57 PM, Martin Kosek wrote: On 10/18/2013 04:28 PM, Petr Viktorin wrote: On 10/03/2013 12:42 PM, Martin Kosek wrote: On 10/02/2013 01:26 PM, Petr Viktorin wrote: On 10/02/2013 01:07 PM, Simo Sorce wrote: ... To sum it up, I would rather not build our permission system on thi

Re: [Freeipa-devel] [PATCHES] 0289-0302 Managed Read permissions

2013-10-21 Thread Martin Kosek
On 10/18/2013 04:28 PM, Petr Viktorin wrote: > On 10/03/2013 12:42 PM, Martin Kosek wrote: >> On 10/02/2013 01:26 PM, Petr Viktorin wrote: >>> On 10/02/2013 01:07 PM, Simo Sorce wrote: >> ... > To sum it up, I would rather not build our permission system on this > group. > > I thi

Re: [Freeipa-devel] [PATCHES] 0289-0302 Managed Read permissions

2013-10-18 Thread Petr Viktorin
On 10/03/2013 12:42 PM, Martin Kosek wrote: On 10/02/2013 01:26 PM, Petr Viktorin wrote: On 10/02/2013 01:07 PM, Simo Sorce wrote: ... To sum it up, I would rather not build our permission system on this group. I think we need top base our ACIs on LDAP bind targets ldap:///all and ldap:///an

Re: [Freeipa-devel] [PATCHES] 0289-0302 Managed Read permissions

2013-10-03 Thread Martin Kosek
On 10/02/2013 01:26 PM, Petr Viktorin wrote: > On 10/02/2013 01:07 PM, Simo Sorce wrote: ... >>> To sum it up, I would rather not build our permission system on this group. >>> >>> I think we need top base our ACIs on LDAP bind targets ldap:///all and >>> ldap:///anyone to avoid performance issues

Re: [Freeipa-devel] [PATCHES] 0289-0302 Managed Read permissions

2013-10-02 Thread Petr Viktorin
On 10/02/2013 01:07 PM, Simo Sorce wrote: - Original Message - On 10/01/2013 10:56 AM, Petr Viktorin wrote: Hello, These patches implement the framework for https://fedorahosted.org/freeipa/ticket/3566 Design is at http://www.freeipa.org/page/V3/Managed_Read_permissions. As you can

Re: [Freeipa-devel] [PATCHES] 0289-0302 Managed Read permissions

2013-10-02 Thread Simo Sorce
- Original Message - > On 10/01/2013 10:56 AM, Petr Viktorin wrote: > > Hello, > > > > These patches implement the framework for > > https://fedorahosted.org/freeipa/ticket/3566 > > > > Design is at http://www.freeipa.org/page/V3/Managed_Read_permissions. > > As you can see from the TOD

Re: [Freeipa-devel] [PATCHES] 0289-0302 Managed Read permissions

2013-10-02 Thread Martin Kosek
On 10/01/2013 10:56 AM, Petr Viktorin wrote: > Hello, > > These patches implement the framework for > https://fedorahosted.org/freeipa/ticket/3566 > > Design is at http://www.freeipa.org/page/V3/Managed_Read_permissions. > As you can see from the TODOs it's not yet complete; I'll need a few more

Re: [Freeipa-devel] [PATCHES] 0289-0302 Managed Read permissions

2013-10-02 Thread Petr Viktorin
On 10/01/2013 09:50 PM, Simo Sorce wrote: - Original Message - On 10/01/2013 10:56 AM, Petr Viktorin wrote: Hello, These patches implement the framework for https://fedorahosted.org/freeipa/ticket/3566 Design is at http://www.freeipa.org/page/V3/Managed_Read_permissions. As you can

Re: [Freeipa-devel] [PATCHES] 0289-0302 Managed Read permissions

2013-10-01 Thread Simo Sorce
- Original Message - > On 10/01/2013 10:56 AM, Petr Viktorin wrote: > > Hello, > > > > These patches implement the framework for > > https://fedorahosted.org/freeipa/ticket/3566 > > > > Design is at http://www.freeipa.org/page/V3/Managed_Read_permissions. > > As you can see from the TODOs

Re: [Freeipa-devel] [PATCHES] 0289-0302 Managed Read permissions

2013-10-01 Thread Petr Viktorin
On 10/01/2013 10:56 AM, Petr Viktorin wrote: Hello, These patches implement the framework for https://fedorahosted.org/freeipa/ticket/3566 Design is at http://www.freeipa.org/page/V3/Managed_Read_permissions. As you can see from the TODOs it's not yet complete; I'll need a few more discussions