2024-12-30 21:07:56 +11:00
|
|
|
dn: cn=sudorole,cn=schema,cn=config
|
|
|
|
objectClass: olcSchemaConfig
|
|
|
|
cn: sudorole
|
|
|
|
olcAttributeTypes: {0}( 1.3.6.1.4.1.15953.9.1.1 NAME 'sudoUser'
|
2023-04-02 11:50:40 +10:00
|
|
|
DESC 'User(s) who may run sudo'
|
|
|
|
EQUALITY caseExactIA5Match
|
|
|
|
SUBSTR caseExactIA5SubstringsMatch
|
|
|
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
2024-12-30 21:07:56 +11:00
|
|
|
olcAttributeTypes: {1}( 1.3.6.1.4.1.15953.9.1.2
|
2023-04-02 11:50:40 +10:00
|
|
|
NAME 'sudoHost'
|
|
|
|
DESC 'Host(s) who may run sudo'
|
|
|
|
EQUALITY caseExactIA5Match
|
|
|
|
SUBSTR caseExactIA5SubstringsMatch
|
|
|
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
2024-12-30 21:07:56 +11:00
|
|
|
olcAttributeTypes: {2}( 1.3.6.1.4.1.15953.9.1.3
|
2023-04-02 11:50:40 +10:00
|
|
|
NAME 'sudoCommand'
|
|
|
|
DESC 'Command(s) to be executed by sudo'
|
|
|
|
EQUALITY caseExactIA5Match
|
|
|
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
2024-12-30 21:07:56 +11:00
|
|
|
olcAttributeTypes: {3}( 1.3.6.1.4.1.15953.9.1.4
|
2023-04-02 11:50:40 +10:00
|
|
|
NAME 'sudoRunAs'
|
|
|
|
DESC 'User(s) impersonated by sudo'
|
|
|
|
EQUALITY caseExactIA5Match
|
|
|
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
2024-12-30 21:07:56 +11:00
|
|
|
olcAttributeTypes: {4}( 1.3.6.1.4.1.15953.9.1.5
|
2023-04-02 11:50:40 +10:00
|
|
|
NAME 'sudoOption'
|
|
|
|
DESC 'Options(s) followed by sudo'
|
|
|
|
EQUALITY caseExactIA5Match
|
|
|
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
2024-12-30 21:07:56 +11:00
|
|
|
olcAttributeTypes: {5}( 1.3.6.1.4.1.15953.9.1.6
|
2023-04-02 11:50:40 +10:00
|
|
|
NAME 'sudoRunAsUser'
|
|
|
|
DESC 'User(s) impersonated by sudo'
|
|
|
|
EQUALITY caseExactIA5Match
|
|
|
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
2024-12-30 21:07:56 +11:00
|
|
|
olcAttributeTypes: {6}( 1.3.6.1.4.1.15953.9.1.7
|
2023-04-02 11:50:40 +10:00
|
|
|
NAME 'sudoRunAsGroup'
|
|
|
|
DESC 'Group(s) impersonated by sudo'
|
|
|
|
EQUALITY caseExactIA5Match
|
|
|
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
2024-12-30 21:07:56 +11:00
|
|
|
olcAttributeTypes: {7}( 1.3.6.1.4.1.15953.9.1.8
|
2023-04-02 11:50:40 +10:00
|
|
|
NAME 'sudoNotBefore'
|
|
|
|
DESC 'Start of time interval for which the entry is valid'
|
|
|
|
EQUALITY generalizedTimeMatch
|
|
|
|
ORDERING generalizedTimeOrderingMatch
|
|
|
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.24 )
|
2024-12-30 21:07:56 +11:00
|
|
|
olcAttributeTypes: {8}( 1.3.6.1.4.1.15953.9.1.9
|
2023-04-02 11:50:40 +10:00
|
|
|
NAME 'sudoNotAfter'
|
|
|
|
DESC 'End of time interval for which the entry is valid'
|
|
|
|
EQUALITY generalizedTimeMatch
|
|
|
|
ORDERING generalizedTimeOrderingMatch
|
|
|
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.24 )
|
2024-12-30 21:07:56 +11:00
|
|
|
olcAttributeTypes: {9} ( 1.3.6.1.4.1.15953.9.1.10
|
2023-04-02 11:50:40 +10:00
|
|
|
NAME 'sudoOrder'
|
|
|
|
DESC 'an integer to order the sudoRole entries'
|
|
|
|
EQUALITY integerMatch
|
|
|
|
ORDERING integerOrderingMatch
|
|
|
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 )
|
2024-12-30 21:07:56 +11:00
|
|
|
olcObjectClasses: {0} ( 1.3.6.1.4.1.15953.9.2.1 NAME 'sudoRole' SUP top STRUCTURAL
|
2023-04-02 11:50:40 +10:00
|
|
|
DESC 'Sudoer Entries'
|
|
|
|
MUST ( cn )
|
|
|
|
MAY ( sudoUser $ sudoHost $ sudoCommand $ sudoRunAs $ sudoRunAsUser $ sudoRunAsGroup $ sudoOption $ sudoNotBefore $ sudoNotAfter $ sudoOrder $ description ) )
|