#4523 permission-add gives confusing error when adding ACI to generated tree
Closed: Fixed None Opened 9 years ago by mkosek.

Generated trees (like sudoers or compat tree) cannot hold permissions. When user tries to add a permission to it, not very helpful message is shown, given that user may not realize the difference between generated tree and any other tree in FreeIPA DIT:

# ipa permission-add test --right read --attrs cn --subtree "cn=compat,dc=mkosek-fedora20,dc=test"
ipa: ERROR: no such entry

I would expect error similar to adding ACI to non-existent DN:

# ipa permission-add test --right read --attrs cn --subtree "cn=bla,dc=mkosek-fedora20,dc=test"
ipa: ERROR: invalid 'ipapermlocation': Entry cn=bla,dc=mkosek-fedora20,dc=test does not exist

master:

  • 061f7ff Raise better error message for permission added to generated tree

ipa-4-1:

  • 0a54b1c Raise better error message for permission added to generated tree

Metadata Update from @mkosek:
- Issue assigned to tbordaz
- Issue set to the milestone: FreeIPA 4.1

7 years ago

Login to comment on this ticket.

Metadata