HBAC rules are supposed to support external hosts. If a host does not exist in IPA then it should get added as an externalHost.
See the netgroup plugin for handling for this feature.
attachment freeipa-rcrit-845-hbac.patch
This ticket is up for grabs. I looked at this a little, attached is my WIP. Things seem to basically work.
master: 3b9da8e
ipa-2-1: dcc3ceb
Metadata Update from @rcritten: - Issue assigned to rcritten - Issue set to the milestone: FreeIPA 2.1.1 (bug fixing)
Login to comment on this ticket.