infra-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Sebb (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (INFRA-18315) Drop security unix group
Date Tue, 18 Jun 2019 17:20:00 GMT

    [ https://issues.apache.org/jira/browse/INFRA-18315?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16866856#comment-16866856
] 

Sebb commented on INFRA-18315:
------------------------------

I created a branch with the suggested update:

https://github.com/sebbASF/infrastructure-puppet/tree/INFRA-18315

I replaced the unix group definition with the project/member group.
For completeness I added the security-pmc definition; it is not currently used.

Note that the security/member group is also used in the auth for [/pmc/openoffice-security]:
https://github.com/sebbASF/infrastructure-puppet/blob/a077e833af323846443b1119bce9b0d290e2d96e/modules/subversion_server/files/authorization/pit-authorization-template#L967

You may wish to restrict this to actual PMC members; if so that can easily be arranged.

It also allows RW access to the public tree at [/infrastructure/site/trunk/content/security]:
https://github.com/sebbASF/infrastructure-puppet/blob/a077e833af323846443b1119bce9b0d290e2d96e/modules/subversion_server/files/authorization/asf-authorization-template#L1111



> Drop security unix group
> ------------------------
>
>                 Key: INFRA-18315
>                 URL: https://issues.apache.org/jira/browse/INFRA-18315
>             Project: Infrastructure
>          Issue Type: Task
>          Components: LDAP
>            Reporter: Sebb
>            Priority: Major
>
> The LDAP unix group 'security' still exists.
> It should probably now be dropped.
> But first this means changing pit-auth:
> security={ldap:cn=security,ou=groups,dc=apache,dc=org}
> to something like
> security={ldap:cn=security,ou=project,ou=groups,dc=apache,dc=org;attr=owner}
> or perhaps attr=member?



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

Mime
View raw message