#5099 Add permission for user to bypass caacl enforcement
Closed: Fixed None Opened 8 years ago by ftweedal.

Currently, even if a principal has permission to write the userCertificate
attribute of principal(s), cert-request will deny certificate issuance unless
there is a caacl rule allowing it. This affects even admin.

Add a permission that suppresses caacl enforcement in cert-request, of which
admin is a member.

Discussion on freeipa-devel: https://www.redhat.com/archives/freeipa-devel/2015-July/msg00110.html


didn't go trough proper triage

master:

  • 6fa14fd Add permission for bypassing CA ACL enforcement

ipa-4-2:

  • ef8f431 Add permission for bypassing CA ACL enforcement

Metadata Update from @ftweedal:
- Issue assigned to ftweedal
- Issue set to the milestone: FreeIPA 4.2.1

7 years ago

Login to comment on this ticket.

Metadata