[Freeipa-devel] Reorganization of Web UI navigation items

Adam Young ayoung at redhat.com
Wed Jun 4 03:50:35 UTC 2014


On 06/02/2014 09:59 AM, Petr Vobornik wrote:
> Hi List,
>
> the purpose if this mail is to start a discussion about reorganization 
> of navigation items. Users are not fond of such change so we should 
> come up with a solution which would last for some time.
>
> Problem:
> UX recommendation is that one menu level should contain maximum of 7 
> items. We have 10 items in Identity, 7 in Policy and 7 in IPA Server. 
> Basically we reached max. capacity of all 1st-level items.
>
How hard and fast is that recommendation?  I realize it is for New 
things, but for an existing?



> Solution:
> Introduce new 1st-level items and redistribute 2nd-level items.
>
> Initial Draft:
>
> Identity (6)
> - Users
> - Groups
These are really two distinct things.  Rarely are you modifying users 
and hosts.
> - Hosts
> - Hostgroups
These would go nicely with HBAC


> - Netgroups
> - Services
>
> Policy (5)  some better name?
> - HBAC
> - SUDO
SUDO seems like it should go with users

> - Automount
Put with hosts
> - Automember
Is this for all LDAP type stuff?  Probably should go with the ACLs in 
policy.

> - SELinux User Maps
>
> Authentication (4)
> - Radius Server Proxy
> - OTP Tokens
> - Password Policy
> - Kerberos Ticket Policy
>
> Infrastructure (6)  some better name?
> - DNS
Make this a top level.  People tend to think of DNS as its own thing.

> - Realm Domains
> - Trust
Maybe these go with Kerberos Ticket policy?  Keep Kerberos with 
Kerberos.  Maybe a Kerberos top level tab?  Authentication?

> - Views
With kerberos
> - ID Ranges
This and Password policy seem like they should be linked.

> - Certificates
Maybe with Kerberos? A Credentials top level item?
Do we really need all certificates together?  User and host certificates are

>
> Permissions (3)
Directory Access Controls.  Maybe  a Directory Admin top level tab?
> - Role Based Access Control
> - Self Service Permissions
> - Delegation
>
> Configuration (1)
> - Global
>
>
> Notes:
> * draft focuses only on first two levels of navigation
> * 'Permission' and 'Configuration' could be merged into old 'IPA Server'
> * 'Views' are related to Identity and Trust, they have no meaning 
> without some kind of trust -> are next to 'Trusts'
> * it's weird to have 'Policy' item and items with "policy" in name to 
> have in 'Authentication'
>
> Comments are welcome




More information about the Freeipa-devel mailing list