#2328 IFP: Use PolicyKit for access control
Closed: cloned-to-github 3 years ago by pbrezina. Opened 9 years ago by jhrozek.

The InfoPipe currently uses a list of UIDs for access control. Stef proposed to use PolicyKit instead.


Fields changed

milestone: NEEDS_TRIAGE => SSSD 1.13 beta
priority: minor => critical
rhbz: => 0

Fields changed

mark: => 0

Notes from meeting with Stef -- in the loop, have a table with users and authorizations for methods. Need to call all this before the method is dispatched at all, otherwise all handlers get polluted.

The authorizations must be put in the XML file. We also need to a very descrictive default which would say that unless said otherwise, only root can call methods.

Very nice to have for 1.13, but not strictly required.

Since it's only nice-to-have for 1.13, moving to backlog.

milestone: SSSD 1.13 beta => SSSD 1.13 backlog
sensitive: => 0

Fields changed

priority: critical => major

This will be important for supporting local users..

milestone: SSSD 1.13 backlog => SSSD 1.15 beta

Fields changed

priority: major => critical

Metadata Update from @jhrozek:
- Issue set to the milestone: SSSD Future releases (no date set yet)

7 years ago

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/3370

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata Update from @pbrezina:
- Issue close_status updated to: cloned-to-github
- Issue status updated to: Closed (was: Open)

3 years ago

Login to comment on this ticket.

Metadata