4b8b032 ACI: define "Read DNS entries from a zone" aci during install

Authored and Committed by frenaud 2 years ago
    ACI: define "Read DNS entries from a zone" aci during install
    
    The ACI "Read DNS entries from a zone" is defined when
    ipa-server-upgrade is run but not for new installations.
    In order to have consistent ACI (same set for new install
    and for install + upgrade), define this ACI in
    install/share/dns.ldif instead of "Allow read access".
    
    Fixes: https://pagure.io/freeipa/issue/9173
    Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
    Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com>
    Reviewed-By: Rob Crittenden <rcritten@redhat.com>
    
        
file modified
+1 -1