#416 acis for self give overly broad access
Closed: Fixed None Opened 13 years ago by simo.

Right now we allow by default "self" to change way too much stuff.
For example we allow a host to bind as itself and change its cn or managedBy entries. We need to trim this list way down to the bare minimum necessary by default, and let admins relax access if they so desire.
Principle of least surprise!


Metadata Update from @simo:
- Issue assigned to rcritten
- Issue set to the milestone: FreeIPA 2.0 - 2010/11

7 years ago

Login to comment on this ticket.

Metadata