On ma, 03 kesä 2019, Patrick Spinler via FreeIPA-users wrote:
Thank you kindly Alexander! I confirm this set of privs and permissions did allow me to issue a user key and cert via certmonger.
It also helped me understand a little better the structure of IPA permissions from the point of view of someone who's done a little bit of LDAP backend work. Examples are useful. :)
You can also follow my blog from 2016 about the same topic: https://vda.li/en/posts/2016/08/30/Creating-permissions-in-FreeIPA/