[Freeipa-devel] Should normal user see his krbt and password policies?

Petr Vobornik pvoborni at redhat.com
Tue May 27 12:28:22 UTC 2014


Recent removal of global read-only ACI affects current self-service page.

Now it displays error dialog with two errors:
* None: password policy not found
* an internal error has occurred

They are results of:
* pwpolicy-show --user=username
* krbtpolicy-show username
commands.

The second one is an obvious bug:
https://fedorahosted.org/freeipa/ticket/4354

The question is whether normal user should see this information or not.

If yes, we should fix default permissions. If not, we should fix Web UI.
-- 
Petr Vobornik




More information about the Freeipa-devel mailing list