summaryrefslogtreecommitdiffstats
path: root/base/server/python
diff options
context:
space:
mode:
authorJack Magne <jmagne@dhcp-16-206.sjc.redhat.com>2016-10-05 18:16:35 -0700
committerMatthew Harmsen <mharmsen@redhat.com>2016-10-10 16:38:07 -0600
commit1e39ab6823390e736bfa1044c8d63306a1fce226 (patch)
tree8fe443bc9f45e904a3a1beb79c2084ef606ca8ab /base/server/python
parent35aff85b5b0c00d301a0122429b54a7ca9a90c7d (diff)
downloadpki-1e39ab6823390e736bfa1044c8d63306a1fce226.tar.gz
pki-1e39ab6823390e736bfa1044c8d63306a1fce226.tar.xz
pki-1e39ab6823390e736bfa1044c8d63306a1fce226.zip
Fix for: Add ability to disallow TPS to enroll a single user on multiple tokens. #1664
This bug was previously not completely fixed where we left a loophole to allow a user to end up with 2 active tokens. This fix closes that loophole. Also: Fix for: Unable to read an encrypted email using renewed tokens. #2483 This fix provides for a new optional renewal based token policy, that allows the user to retain or recover old encryption certs for that profile, that get overwritten by the renewal process. An example is: RENEW=YES;RENEW_KEEP_OLD_ENC_CERTS=YES The default is YESk you have to explicitly set it to NO to turn it off. The second part of the policy is new. When this is set to "YES", the system will make sure the old enc cert will remain on the token. If it's missing or "NO", no such attempt will be made. junk
Diffstat (limited to 'base/server/python')
0 files changed, 0 insertions, 0 deletions