Project

General

Profile

Actions

tickets #161900

closed

Permissions to edit VPN group

Added by crameleon 24 days ago. Updated 24 days ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
FreeIPA/Kanidm
Target version:
-
Start date:
2024-06-06
Due date:
% Done:

0%

Estimated time:

Description

Hi,

as part of onboarding a new user we need to add them to the vpn group. I took the liberty to refactor your existing SSH key management page to add the instructions there: https://progress.opensuse.org/projects/opensuse-admin-wiki/wiki/Kanidm_Account_Management, but noticed I'm not authorized to modify the vpn group:

crameleon@thor1:/home/crameleon> kanidm group add-members vpn wombelix
2024-06-06T19:29:44.362310Z ERROR kanidm_cli: HTTP Error: 403 Forbidden AccessDenied "b5ea6d43-508f-4604-9c49-e331b2f5beb8"
crameleon@thor1:/home/crameleon> kanidm group add-members vpn@infra.opensuse.org wombelix
2024-06-06T19:29:53.621948Z ERROR kanidm_cli: HTTP Error: 403 Forbidden AccessDenied "fce2057a-8436-4a50-8ea0-bdaba87dc99c"

Ideally, everyone who can add new users should also be able to add them to the vpn group (previously, we did this through the FreeIPA GUI as well).
Could we have this please? :-)

Cheers
Georg

Actions

Also available in: Atom PDF