Mapping LDAP group to user roles

Tanous, Ed ed.tanous at intel.com
Wed Aug 22 01:21:49 AEST 2018


> 
> We have a requirement to assign role to the LDAP users, so certain
> operations can be restricted for users without admin permissions.
> 

It would be great if you could document your proposal as a patch to the existing user management document here:
https://github.com/openbmc/docs/blob/master/user_management.md

It would make it much easier to see what changes you're proposing.  Given what already exists, your proposal is a little confusing, as there's already a mechanism to get group membership, and defined the user roles.  Are you proposing changing the existing interfaces to the new group collection type interface?  You're proposing two user roles, but we already have documented 4 user roles.  Is your proposal to delete two of them?

I think all of these questions would be answered if you could update the document above with your proposed changes.


More information about the openbmc mailing list