This file is indexed.

/usr/share/ipa/updates/45-roles.update is in freeipa-server 4.7.0~pre1+git20180411-2ubuntu2.

This file is owned by root:root, with mode 0o644.

The actual contents of the file can be viewed below.

  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
# Helpdesk roles
dn: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,$SUFFIX
default:objectClass: top
default:objectClass: groupofnames
default:objectClass: nestedgroup
default:cn: Modify Users and Reset passwords
default:description: Modify Users and Reset passwords
default:member: cn=helpdesk,cn=roles,cn=accounts,$SUFFIX

dn: cn=Modify Group membership,cn=privileges,cn=pbac,$SUFFIX
default:objectClass: top
default:objectClass: groupofnames
default:objectClass: nestedgroup
default:cn: Modify Group membership
default:description: Modify Group membership
default:member: cn=helpdesk,cn=roles,cn=accounts,$SUFFIX

dn: cn=User Administrator,cn=roles,cn=accounts,$SUFFIX
default:objectClass: groupofnames
default:objectClass: nestedgroup
default:objectClass: top
default:cn: User Administrator
default:description: Responsible for creating Users and Groups

dn: cn=User Administrators,cn=privileges,cn=pbac,$SUFFIX
add: member: cn=User Administrator,cn=roles,cn=accounts,$SUFFIX

dn: cn=Group Administrators,cn=privileges,cn=pbac,$SUFFIX
add: member: cn=User Administrator,cn=roles,cn=accounts,$SUFFIX

dn: cn=Stage User Administrators,cn=privileges,cn=pbac,$SUFFIX
default:objectClass: groupofnames
default:objectClass: nestedgroup
default:objectClass: top
default:cn: Stage User Administrators
default:description: Stage User Administrators
add: member: cn=User Administrator,cn=roles,cn=accounts,$SUFFIX

dn: cn=IT Specialist,cn=roles,cn=accounts,$SUFFIX
default:objectClass: groupofnames
default:objectClass: nestedgroup
default:objectClass: top
default:cn: IT Specialist
default:description: IT Specialist

dn: cn=Host Administrators,cn=privileges,cn=pbac,$SUFFIX
add:member: cn=IT Specialist,cn=roles,cn=accounts,$SUFFIX

dn: cn=Host Group Administrators,cn=privileges,cn=pbac,$SUFFIX
add:member: cn=IT Specialist,cn=roles,cn=accounts,$SUFFIX

dn: cn=Service Administrators,cn=privileges,cn=pbac,$SUFFIX
add:member: cn=IT Specialist,cn=roles,cn=accounts,$SUFFIX

dn: cn=Automount Administrators,cn=privileges,cn=pbac,$SUFFIX
add:member: cn=IT Specialist,cn=roles,cn=accounts,$SUFFIX

dn: cn=IT Security Specialist,cn=roles,cn=accounts,$SUFFIX
default:objectClass: groupofnames
default:objectClass: nestedgroup
default:objectClass: top
default:cn: IT Security Specialist
default:description: IT Security Specialist

dn: cn=Netgroups Administrators,cn=privileges,cn=pbac,$SUFFIX
add:member: cn=IT Security Specialist,cn=roles,cn=accounts,$SUFFIX

dn: cn=HBAC Administrator,cn=privileges,cn=pbac,$SUFFIX
add:member: cn=IT Security Specialist,cn=roles,cn=accounts,$SUFFIX

dn: cn=Sudo administrator,cn=privileges,cn=pbac,$SUFFIX
add:member: cn=IT Security Specialist,cn=roles,cn=accounts,$SUFFIX

dn: cn=Security Architect,cn=roles,cn=accounts,$SUFFIX
default:objectClass: groupofnames
default:objectClass: nestedgroup
default:objectClass: top
default:cn: Security Architect
default:description: Security Architect

dn: cn=Delegation Administrator,cn=privileges,cn=pbac,$SUFFIX
add:member: cn=Security Architect,cn=roles,cn=accounts,$SUFFIX

dn: cn=Replication Administrators,cn=privileges,cn=pbac,$SUFFIX
add:member: cn=ipaservers,cn=hostgroups,cn=accounts,$SUFFIX
add:member: cn=Security Architect,cn=roles,cn=accounts,$SUFFIX

dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,$SUFFIX
add:member: cn=Security Architect,cn=roles,cn=accounts,$SUFFIX

dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,$SUFFIX
add:member: cn=Security Architect,cn=roles,cn=accounts,$SUFFIX

dn: cn=Enrollment Administrator,cn=roles,cn=accounts,$SUFFIX
default:objectClass: groupofnames
default:objectClass: nestedgroup
default:objectClass: top
default:cn: Enrollment Administrator
default:description: Enrollment Administrator responsible for client(host) enrollment

dn: cn=Host Enrollment,cn=privileges,cn=pbac,$SUFFIX
add:member: cn=Enrollment Administrator,cn=roles,cn=accounts,$SUFFIX