Dotfiles/setup/modules/FreeipaAnsible
Amir Alexander Abdelbaki cd2f1424c7 feat(freeipa-ansible): split login monitoring and add usr_ctl capability grants
Split usr_mon_logins into three focused checks: failed local (console/
tty/greeter) logins, SSH logins (usr_mon_sshlogins), and sudo/SELinux/
AppArmor rights violations (usr_mon_rightsviolations) — plus a new
usr_mon_iploc check that flags public-IP geolocation country changes.

Add usr_ctl_dnshostfile, usr_ctl_netman, and usr_ctl_wifi policies that
grant members scoped, non-root capability (hosts file ACL, NetworkManager
connection permissions) resolved from IPA group membership and
re-applied every enforcer tick.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 09:06:34 +02:00
..
ansible feat(freeipa-ansible): split login monitoring and add usr_ctl capability grants 2026-07-23 09:06:34 +02:00
autofs-pkgbuild fix(ansipa): FreeIPA enrollment for Arch/Fedora/RHEL + autofs AUR workaround 2026-07-02 11:27:46 +02:00
image feat(freeipa-ansible): split login monitoring and add usr_ctl capability grants 2026-07-23 09:06:34 +02:00
auto-enroll-ansible.sh Update setup/modules/FreeipaAnsible/auto-enroll-ansible.sh 2026-04-27 16:38:02 +02:00
copilot-explains.txt Update setup/modules/FreeipaAnsible/copilot-explains.txt 2026-04-27 17:00:37 +02:00
freeipa-client-answerfile.json setup: add FreeIPA server module and generic client script 2026-05-18 11:12:31 +02:00
freeipa-client.sh fix(ansipa): FreeIPA enrollment for Arch/Fedora/RHEL + autofs AUR workaround 2026-07-02 11:27:46 +02:00
freeipa-enroll.sh fix(ansipa): FreeIPA enrollment for Arch/Fedora/RHEL + autofs AUR workaround 2026-07-02 11:27:46 +02:00