e137f30 aci: allow members of ipaservers to set up replication

Authored and Committed by jcholast 8 years ago
    aci: allow members of ipaservers to set up replication
    
    Add ACIs which allow the members of the ipaservers host group to set up
    replication. This allows IPA hosts to perform replica promotion on
    themselves.
    
    A number of checks which need read access to certain LDAP entries is done
    during replica promotion. Add ACIs to allow these checks to be done using
    any valid IPA host credentials.
    
    https://fedorahosted.org/freeipa/ticket/5401
    
    Reviewed-By: Martin Basti <mbasti@redhat.com>
    Reviewed-By: Simo Sorce <ssorce@redhat.com>
    
        
file modified
+25 -0