It would be very nice to have some way to set a rule for a "category" or group of services. It is very error-prone to administer the same set of rules for example for ssh, su, login separately and add them to different HBAC rules.
This bug is also tracked in RH bugzilla https://bugzilla.redhat.com/show_bug.cgi?id=588574
On http://freeipa.org/page/PAMServices the necessary changes on the server side are described. The IPA access provider must be updated accordingly.
Fields changed
milestone: NEEDS_TRIAGE => SSSD 1.2.0
Fixed by eb812bb807d65309c037c6a806b728c637e9b0fa
component: SSSD => IPA Provider doc: 0 => 1 fixedin: => 1.2.0 resolution: => fixed status: new => closed tests: 0 => 1
Pretty sure this is what serviceCategory and memberService attributes are for. Will doc this when I do the HBAC doc, and probably man page?
https://bugzilla.redhat.com/show_bug.cgi?id=598314
The documentation should mention chapter of the IPA documentation where HBAC rules are described.
rhbz: => [https://bugzilla.redhat.com/show_bug.cgi?id=588574 588574]
Metadata Update from @sbose: - Issue assigned to sbose - Issue set to the milestone: SSSD 1.2.0
SSSD is moving from Pagure to Github. This means that new issues and pull requests will be accepted only in SSSD's github repository.
This issue has been cloned to Github and is available here: - https://github.com/SSSD/sssd/issues/1517
If you want to receive further updates on the issue, please navigate to the github issue and click on subscribe button.
subscribe
Thank you for understanding. We apologize for all inconvenience.