Ñò
Ã#xPc @ s¦ d d k l Z l Z l Z d d k l Z l Z d d k l Z d d k l Z l Z l Z d d k l
Z
d d k l Z l Z d d k
l Z e d ƒ Z d Z e d
d e d ƒ ƒf Z d
e f d „ ƒ YZ e i e ƒ d e i f d „ ƒ YZ e i e ƒ d e i f d „ ƒ YZ e i e ƒ d e i f d „ ƒ YZ e i e ƒ d e i f d „ ƒ YZ e i e ƒ d e i f d „ ƒ YZ e i e ƒ d S( iÿÿÿÿ( t apit _t ngettext( t Flagt Str( t context( R t crudt errors( t output( t Objectt Command( t gen_pkey_only_optionsÍ
Group to Group Delegation
A permission enables fine-grained delegation of permissions. Access Control
Rules, or instructions (ACIs), grant permission to permissions to perform
given tasks such as adding a user, modifying a group, etc.
Group to Group Delegations grants the members of one group to update a set
of attributes of members of another group.
EXAMPLES:
Add a delegation rule to allow managers to edit employee's addresses:
ipa delegation-add --attrs=street --group=managers --membergroup=employees "managers edit employees' street"
When managing the list of attributes you need to include all attributes
in the list, including existing ones. Add postalCode to the list:
ipa delegation-mod --attrs=street,postalCode --group=managers --membergroup=employees "managers edit employees' street"
Display our updated rule:
ipa delegation-show "managers edit employees' street"
Delete a rule:
ipa delegation-del "managers edit employees' street"
u
delegationt acit labelt ACIt
delegationc B s: e Z d Z e Z e d ƒ Z e d ƒ Z e d ƒ Z e d ƒ Z e
d d d d e d ƒ d
e d ƒ d e ƒe
d d d
d e d ƒ d
e d ƒ d e ƒe
d d d d e d ƒ d
e d ƒ d e d d „ ƒe
d d d d e d ƒ d
e d ƒ ƒe
d d d d e d ƒ d
e d ƒ ƒf Z d „ Z
d „ Z RS( s
Delegation object.
R t delegationst Delegationst
Delegationt acinamet cli_namet nameR
s Delegation namet doct primary_keys permissions*t permissionst PermissionssM Comma-separated list of permissions to grant (read, write). Default is write.t csvs attrs+t attrst
Attributess" Comma-separated list of attributest
normalizerc C s
| i ƒ S( ( t lower( t value( ( s= /usr/lib/python2.6/site-packages/ipalib/plugins/delegation.pyt