summaryrefslogtreecommitdiffstats
path: root/util/ipa_mspac.h
Commit message (Collapse)AuthorAgeFilesLines
* ipa-kdb: read SID blacklist from LDAPMartin Kosek2013-02-121-0/+32
SIDs in incoming MS-PAC were checked and filtered with a fixed list of well-known SIDs. Allow reading the SID blacklist from LDAP (ipaNTSIDBlacklistIncoming and ipaNTSIDBlacklistOutgoing) and add the list to mspac adtrust structure. Use the hardcoded SID list only if the LDAP SID list is not configured. LIMITATION: SID blacklist list is not used yet. https://fedorahosted.org/freeipa/ticket/3289