Re: [Freeipa-users] hbac service allowed despite not listed

2015-11-24 Thread Jakub Hrozek
On Tue, Nov 24, 2015 at 10:25:11AM +0100, Winfried de Heiden wrote: >Hi all, > >sss_debuglevel 6; in /var/log/sss/sssd_pam.log > >Running as "testuser" crond is denied; perfecr since it is not listed in >the HBAC services. > >[testuser@fedora23-server ~]$ crontab -l >You

Re: [Freeipa-users] hbac service allowed despite not listed

2015-11-24 Thread Winfried de Heiden
Hi all, Running as an ordinary user, straight from the beginning. Is the (default) suid of/usr/bin/su causing this?   Anyway: the info requested: /var/log/secure will tell: Nov 24 11:04:11 fedora23-server su:

Re: [Freeipa-users] hbac service allowed despite not listed

2015-11-24 Thread Jakub Hrozek
On Tue, Nov 24, 2015 at 11:10:11AM +0100, Winfried de Heiden wrote: >Hi all, > >Running as an ordinary user, straight from the beginning. > >Is the (default) suid of/usr/bin/su causing this? >  >Anyway: the info requested: > >/var/log/secure will tell: >Nov 24

Re: [Freeipa-users] hbac service allowed despite not listed

2015-11-24 Thread Winfried de Heiden
Hi all, sss_debuglevel 6; in /var/log/sss/sssd_pam.log Running as "testuser" crond is denied; perfecr since it is not listed in the HBAC services. [testuser@fedora23-server ~]$ crontab -l You (testuser) are not allowed to access

Re: [Freeipa-users] hbac service allowed despite not listed

2015-11-24 Thread Jakub Hrozek
On Tue, Nov 24, 2015 at 11:10:11AM +0100, Winfried de Heiden wrote: >Hi all, > >Running as an ordinary user, straight from the beginning. > >Is the (default) suid of/usr/bin/su causing this? >  >Anyway: the info requested: > >/var/log/secure will tell: >Nov 24

Re: [Freeipa-users] hbac service allowed despite not listed

2015-11-24 Thread Winfried de Heiden
Hi all, The problem is clear, there is a misunderstanding of the service "su" and "su-l", this is about the target users. Hence; su - to user winfried is allowed since su and su-l are added to the hbac service list of this user. This looks a bit strange from the ui perspective, all other

Re: [Freeipa-users] hbac service allowed despite not listed

2015-11-24 Thread Alexander Bokovoy
On Tue, 24 Nov 2015, Winfried de Heiden wrote: Hi all, The problem is clear, there is a misunderstanding of the service "su" and "su-l", this is about the target users. Hence; su - to user winfried is allowed since su and su-l are added to the hbac service list of this user. This looks a

Re: [Freeipa-users] hbac service allowed despite not listed

2015-11-24 Thread Jakub Hrozek
On Tue, Nov 24, 2015 at 12:58:42PM +0100, Winfried de Heiden wrote: > Hi all, > > [winfried@ipa ~]$ ipa hbacrule-show allow_all > Rule name: allow_all > User category: all > Host category: all > Service category: all > Description: Allow all users to access any host from any host >

[Freeipa-users] hbac service allowed despite not listed

2015-11-23 Thread Winfried de Heiden
Hi all, I created some hbac rule on freeipa-server 4.1.4 on Fedora 22 # ipa hbacrule-show testuser   Rule name: testuser   Enabled: TRUE   Users: testuser   Hosts: fedora23-server.blabla.bla   Services: sshd Hence, "

Re: [Freeipa-users] hbac service allowed despite not listed

2015-11-23 Thread Jakub Hrozek
On Mon, Nov 23, 2015 at 04:55:31PM +0100, Winfried de Heiden wrote: >Hi all, > >I created some hbac rule on freeipa-server 4.1.4 on Fedora 22 > ># ipa hbacrule-show testuser >  Rule name: testuser >  Enabled: TRUE >  Users: testuser >  Hosts:

Re: [Freeipa-users] hbac service allowed despite not listed

2015-11-23 Thread Sumit Bose
On Mon, Nov 23, 2015 at 05:16:26PM +0100, Jakub Hrozek wrote: > On Mon, Nov 23, 2015 at 04:55:31PM +0100, Winfried de Heiden wrote: > >Hi all, > > > >I created some hbac rule on freeipa-server 4.1.4 on Fedora 22 > > > ># ipa hbacrule-show testuser > >  Rule name: testuser > >