| Privilege | Associated Permissions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Automount Administrators |
| |||||||||
| Certificate Administrators |
| |||||||||
| Delegation Administrator |
| |||||||||
| DNS Administrators (for users) |
| |||||||||
| DNS Servers (for machines) |
| |||||||||
| Group Administrators |
| |||||||||
| HBAC Administrator |
| |||||||||
| Host Administrators |
| |||||||||
| Host Enrollment |
| |||||||||
| Host Group Administrators |
| |||||||||
| Modify Users and Reset Passwords |
| |||||||||
| Netgroups Administrators |
| |||||||||
| Password Policy Administrator |
| |||||||||
| Replication Administrators[a] |
| |||||||||
| Service Administrators |
| |||||||||
| Sudo Administrator |
| |||||||||
| User Administrators |
| |||||||||
| Write IPA Configuration |
| |||||||||
[a]
This permission can only be granted to servers, not to users.
| ||||||||||




# ipa role-add --desc="User Administrator" useradmin ------------------------ Added role "useradmin" ------------------------ Role name: useradmin Description: User Administrator
# ipa role-add-privilege --privileges="User Administrators" useradmin Role name: useradmin Description: User Administrator Privileges: user administrators ---------------------------- Number of privileges added 1 ----------------------------
useradmin, which already exists.
# ipa role-add-member --groups=useradmins useradmin Role name: useradmin Description: User Administrator Member groups: useradmins Privileges: user administrators ------------------------- Number of members added 1 -------------------------


permission-add command. All permissions require a list of allowed actions (--permissions), but the way that the target entries for the ACI are selected can be different. There are four options:
$ ipa permission-add "manage Windows groups" --filter="posixGroup=false" --permissions=writepermission-add command does not validate the given LDAP filter. Verify that the filter returns the expected results before configuring the permission.
$ ipa permission-add "manage automount locations" --subtree="ldap://ldap.example.com:389/cn=automount,dc=example,dc=com" --permissions=write--attrs option, in a comma-separated list.
$ ipa permission-add "manage service" --permissions=all --type=service --attrs=krbprincipalkey,krbprincipalname,managedby
--attrs) must exist and be allowed attributes for the given object type, or the permission operation fails with schema syntax errors.




privilege-add command, and then permissions are added to the privilege group using the privilege-add-permission command.
$ ipa privilege-add "managing filesystems" --desc="for filesystems"
$ ipa privilege-add-permission "managing filesystems" --permissions="managing automount","managing ftp services"