[Freeipa-users] Re: password reset privileges

2017-08-10 Thread Rob Crittenden via FreeIPA-users
Tiemen Ruiten wrote: > Hello, > > Sorry for the late reply. This is the latest FreeIPA version in CentOS > 7.3 (4.4.0-14). > > Indeed the helpdesk role should be sufficient. I tried with the User > Administrator role as well, but that made no difference. Since it's > working for you, it's

[Freeipa-users] Re: password reset privileges

2017-08-09 Thread Tiemen Ruiten via FreeIPA-users
Hello, Sorry for the late reply. This is the latest FreeIPA version in CentOS 7.3 (4.4.0-14). Indeed the helpdesk role should be sufficient. I tried with the User Administrator role as well, but that made no difference. Since it's working for you, it's likely a config error, but I have no idea

[Freeipa-users] Re: password reset privileges

2017-08-04 Thread Rob Crittenden via FreeIPA-users
Tiemen Ruiten via FreeIPA-users wrote: > As I mentioned in my first mail, that doesn't work. For testing, I > created a new role that contains the following privileges: > > Group Administrators > Modify Group membership > Modify Users and Reset passwords > User Administrators > > Unfortunately,

[Freeipa-users] Re: password reset privileges

2017-08-04 Thread Tiemen Ruiten via FreeIPA-users
As I mentioned in my first mail, that doesn't work. For testing, I created a new role that contains the following privileges: Group Administrators Modify Group membership Modify Users and Reset passwords User Administrators Unfortunately, I get the same error. On 4 August 2017 at 17:40, Bob

[Freeipa-users] Re: password reset privileges

2017-08-04 Thread Bob Rentschler via FreeIPA-users
Assigning roles to your userwill fix that issue. The existing "User Administrator" role may fit your needs, but I am unsure how restrictive you want to be with permissions. If you want to be more restrictive a custom role with "System: Change User password" permissions would seem to be the right