Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-19134

[ansible-freeipa] ipadnszone: Add support for per-zone privilege delegation

    • ansible-freeipa-1.12.1-1.el9
    • None
    • None
    • 1
    • rhel-sst-idm-ipa
    • ssg_idm
    • 24
    • 25
    • 5
    • QE ack, Dev ack
    • False
    • Hide

      None

      Show
      None
    • Yes
    • 2024-Q1-Alpha-S4
    • Enhancement
    • Hide
      .The delegation of DNS zone management is now enabled in `ansible-freeipa`

      You can now use the `dnszone` `ansible-freeipa` module to delegate DNS zone management. Use the `permission` or `managedby` variable of the `dnszone` module to configure a per-zone access delegation permission.
      Show
      .The delegation of DNS zone management is now enabled in `ansible-freeipa` You can now use the `dnszone` `ansible-freeipa` module to delegate DNS zone management. Use the `permission` or `managedby` variable of the `dnszone` module to configure a per-zone access delegation permission.
    • Done
    • None

      IPA DNS Zones management can be delegated by adding a "Manage DNS zone" permission. The CLI commands that manage these permissions are dnszone-add-delegation and dnszone-remove-delegation.

      The ansible-freeipa module ipadnszone did not have this capability, and it now support dnszone per-zone management delegation by setting the module parameter 'permission'. If set to 'true' the permission will be assigned to the zone, if set to false the permission will be removed.

            [RHEL-19134] [ansible-freeipa] ipadnszone: Add support for per-zone privilege delegation

            Errata Tool added a comment -

            Since the problem described in this issue should be resolved in a recent advisory, it has been closed.

            For information on the advisory (ansible-freeipa bug fix and enhancement update), and where to find the updated files, follow the link below.

            If the solution does not work for you, open a new bug report.
            https://access.redhat.com/errata/RHBA-2024:2237

            Errata Tool added a comment - Since the problem described in this issue should be resolved in a recent advisory, it has been closed. For information on the advisory (ansible-freeipa bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2024:2237

            Verified
            ansible-core-2.14.14-1.el9.x86_64
            ansible-freeipa-1.12.1-1.el9.noarch

            Test Result:

             PASSED ansible_freeipa_tests/dns/test_dns.py::TestDNSForwardZone::test_dnsforwardzone_grant_system_permission
             PASSED ansible_freeipa_tests/dns/test_dns.py::TestDNSForwardZone::test_dnsforwardzone_removed_system_permission
             PASSED ansible_freeipa_tests/dns/test_dns.py::TestDNSZone::test_dnszone_grant_system_permission
             PASSED ansible_freeipa_tests/dns/test_dns.py::TestDNSZone::test_dnszone_removed_system_permission 

            Based on the test result, marking the issue as "Release Pending"(Verified)

            Varun Mylaraiah added a comment - Verified ansible-core-2.14.14-1.el9.x86_64 ansible-freeipa-1.12.1-1.el9.noarch Test Result: PASSED ansible_freeipa_tests/dns/test_dns.py::TestDNSForwardZone::test_dnsforwardzone_grant_system_permission  PASSED ansible_freeipa_tests/dns/test_dns.py::TestDNSForwardZone::test_dnsforwardzone_removed_system_permission  PASSED ansible_freeipa_tests/dns/test_dns.py::TestDNSZone::test_dnszone_grant_system_permission  PASSED ansible_freeipa_tests/dns/test_dns.py::TestDNSZone::test_dnszone_removed_system_permission Based on the test result, marking the issue as "Release Pending"(Verified)

            gitlab-bot added a comment -

            Thomas Woerner mentioned this issue in a merge request of Red Hat / centos-stream / rpms / ansible-freeipa on branch af_1_12_1:

            Update to version 1.12.1...

            gitlab-bot added a comment - Thomas Woerner mentioned this issue in a merge request of Red Hat / centos-stream / rpms / ansible-freeipa on branch af_1_12_1 : Update to version 1.12.1...

            Rafael Jeffman added a comment - Upstream PR: https://github.com/freeipa/ansible-freeipa/pull/1147

              rjeffman@redhat.com Rafael Jeffman
              twoerner Thomas Woerner
              Thomas Woerner Thomas Woerner
              Varun Mylaraiah Varun Mylaraiah
              Filip Hanzelka Filip Hanzelka
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: