Hi,

On Mon, May 15, 2023 at 10:34 PM Omar Pagan via FreeIPA-users <freeipa-users@lists.fedorahosted.org> wrote:
[root @ ldap01] ~
$ ipa hbactest --user gr031529 --host deepcore-bastion.uaap.maxar.com --service ssh
The issue looks like a simple typo. Here the test is using ssh service...
--------------------
Access granted: True
--------------------
  Matched rules: allow_all
  Not matched rules: admins_allow_all
  Not matched rules: allow_systemd-user
  Not matched rules: cpaac-bastion
  Not matched rules: darc_admins_hbac
  Not matched rules: deepcore-bastion
  Not matched rules: shared-services-hbac

[root @ ldap01] ~
$ ipa hbacrule-show deepcore-bastion
  Rule name: deepcore-bastion
  Enabled: True
  User Groups: deepcore, amod-bastion
  Hosts: deepcore-bastion.uaap.maxar.com
  HBAC Services: sshd
... but the rule is defined for sshd instead of ssh.
HTH,
flo


Even after adding the service to the rule, and testing against the correct host, it doesn't match the rule.
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-leave@lists.fedorahosted.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue