Hi,

On Wed, May 10, 2023 at 1:37 PM Omar Pagan via FreeIPA-users <
[email protected]> wrote:

> Hello,
> I have setup a bastion host with an IPA client in order to control access
> to the bastion host by groups.  I have users in different groups, but I
> just got word that people outside the group / HBAC rule can access and
> login with their IPA credentials.  Everything seems okay with the
> configuration.
> I have uninstalled and re-installed the client, generating a new SSSD
> config file, yet the user still accessing the bastion host.  Thoughts?
>

Can you show the full list of hbac rules obtained with *ipa hbacrule-find*?
You can also try to diagnose using for instance *ipa hbactest --user <user>
--host <host>* *--service ssh* as it should show which rule allows access.

flo

> _______________________________________________
> FreeIPA-users mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
> Fedora Code of Conduct:
> https://docs.fedoraproject.org/en-US/project/code-of-conduct/
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives:
> https://lists.fedorahosted.org/archives/list/[email protected]
> Do not reply to spam, report it:
> https://pagure.io/fedora-infrastructure/new_issue
>
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to