<feed xmlns='http://www.w3.org/2005/Atom'>
<title>sssd.git/src/providers, branch refactor-fo</title>
<subtitle>sssd with jhrozek's patches</subtitle>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/'/>
<entry>
<title>heimdal: use sss_krb5_princ_realm to access realm</title>
<updated>2012-07-09T12:41:19+00:00</updated>
<author>
<name>Rambaldi</name>
<email>gentoo@xs4me.net</email>
</author>
<published>2012-07-07T11:37:45+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=bb446567389e894bf4d64a9589606d1951ac7902'/>
<id>bb446567389e894bf4d64a9589606d1951ac7902</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Revert commit 4c157ecedd52602f75574605ef48d0c48e9bfbe8</title>
<updated>2012-07-06T17:19:32+00:00</updated>
<author>
<name>Stef Walter</name>
<email>stefw@gnome.org</email>
</author>
<published>2012-07-06T17:06:48+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=aa2c6f469414668e56aa03d5ba5cecde64bc713e'/>
<id>aa2c6f469414668e56aa03d5ba5cecde64bc713e</id>
<content type='text'>
 * This broke corner cases when used with
      default_tkt_types = des-cbc-crc
   and DES enabled on an AD domain.
 * This is fixed in kerberos instead, in a more correct way
   and in a way which we cannot replicate.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
 * This broke corner cases when used with
      default_tkt_types = des-cbc-crc
   and DES enabled on an AD domain.
 * This is fixed in kerberos instead, in a more correct way
   and in a way which we cannot replicate.
</pre>
</div>
</content>
</entry>
<entry>
<title>AD: Force case-insensitive operation in AD provider</title>
<updated>2012-07-06T15:44:46+00:00</updated>
<author>
<name>Stephen Gallagher</name>
<email>sgallagh@redhat.com</email>
</author>
<published>2012-07-06T00:44:24+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=346f41f1ede975cb2db0af570f5b454b9b306704'/>
<id>346f41f1ede975cb2db0af570f5b454b9b306704</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>AD: use krb5_keytab for validation and GSSAPI</title>
<updated>2012-07-06T15:44:46+00:00</updated>
<author>
<name>Stephen Gallagher</name>
<email>sgallagh@redhat.com</email>
</author>
<published>2012-07-06T00:00:37+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=4e2d9fe30bf8b692972a9654c60d2d90ed355815'/>
<id>4e2d9fe30bf8b692972a9654c60d2d90ed355815</id>
<content type='text'>
This simplifies configuration by eliminating the need to
specifiy both krb5_keytab and ldap_krb5_keytab if the keytab is
not located at /etc/krb5.keytab
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This simplifies configuration by eliminating the need to
specifiy both krb5_keytab and ldap_krb5_keytab if the keytab is
not located at /etc/krb5.keytab
</pre>
</div>
</content>
</entry>
<entry>
<title>AD: Add AD access-control provider</title>
<updated>2012-07-06T15:44:46+00:00</updated>
<author>
<name>Stephen Gallagher</name>
<email>sgallagh@redhat.com</email>
</author>
<published>2012-07-02T14:34:52+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=a4cce2c98eedecb5d3b47da62104634cae268434'/>
<id>a4cce2c98eedecb5d3b47da62104634cae268434</id>
<content type='text'>
This patch adds support for checking whether a user is expired or
disabled in AD.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This patch adds support for checking whether a user is expired or
disabled in AD.
</pre>
</div>
</content>
</entry>
<entry>
<title>AD: Add AD auth and chpass providers</title>
<updated>2012-07-06T15:44:45+00:00</updated>
<author>
<name>Stephen Gallagher</name>
<email>sgallagh@redhat.com</email>
</author>
<published>2012-06-28T01:38:13+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=d92c50f6d75ae980b0d130134112a33e1584724c'/>
<id>d92c50f6d75ae980b0d130134112a33e1584724c</id>
<content type='text'>
These new providers take advantage of existing code for the KRB5
provider, providing sensible defaults for operating against an
Active Directory 2008 R2 or later server.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
These new providers take advantage of existing code for the KRB5
provider, providing sensible defaults for operating against an
Active Directory 2008 R2 or later server.
</pre>
</div>
</content>
</entry>
<entry>
<title>AD: Add AD identity provider</title>
<updated>2012-07-06T15:44:45+00:00</updated>
<author>
<name>Stephen Gallagher</name>
<email>sgallagh@redhat.com</email>
</author>
<published>2012-03-27T01:41:28+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=effcbdb12c7ef892f1fd92a745cb33a08ca4ba30'/>
<id>effcbdb12c7ef892f1fd92a745cb33a08ca4ba30</id>
<content type='text'>
This new identity provider takes advantage of existing code for
the LDAP provider, but provides sensible defaults for operating
against an Active Directory 2008 R2 or later server.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This new identity provider takes advantage of existing code for
the LDAP provider, but provides sensible defaults for operating
against an Active Directory 2008 R2 or later server.
</pre>
</div>
</content>
</entry>
<entry>
<title>LDAP: Rename user and group maps for AD</title>
<updated>2012-07-06T15:44:45+00:00</updated>
<author>
<name>Stephen Gallagher</name>
<email>sgallagh@redhat.com</email>
</author>
<published>2012-04-10T01:13:41+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=42aeb975864c3c3ba971fd04c61a1aaf6e69905b'/>
<id>42aeb975864c3c3ba971fd04c61a1aaf6e69905b</id>
<content type='text'>
This will eliminate ambiguity for the AD provider
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This will eliminate ambiguity for the AD provider
</pre>
</div>
</content>
</entry>
<entry>
<title>KRB5: Create a common init routine for krb5_child options</title>
<updated>2012-07-06T15:44:45+00:00</updated>
<author>
<name>Stephen Gallagher</name>
<email>sgallagh@redhat.com</email>
</author>
<published>2012-06-27T18:07:05+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=3441d0c2d11aea0c39b009751a1898333c009674'/>
<id>3441d0c2d11aea0c39b009751a1898333c009674</id>
<content type='text'>
This will reduce code duplication between the krb5, ipa and ad
providers
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This will reduce code duplication between the krb5, ipa and ad
providers
</pre>
</div>
</content>
</entry>
<entry>
<title>KRB5: Drop memctx parameter of krb5_try_kdcip</title>
<updated>2012-07-06T15:44:45+00:00</updated>
<author>
<name>Stephen Gallagher</name>
<email>sgallagh@redhat.com</email>
</author>
<published>2012-06-27T13:59:57+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=69905bf968003216d444fc68d8597e139362f2e6'/>
<id>69905bf968003216d444fc68d8597e139362f2e6</id>
<content type='text'>
This function is not supposed to return any newly-allocated memory
directly. It was actually leaking the memory for krb5_servers if
krb5_kdcip was being used, though it was undetectable because it
was allocated on the provided memctx.

This patch removes the memctx parameter and allocates krb5_servers
temporarily on NULL and ensures that it is freed on all exit
conditions. It is not necessary to retain this memory, as
dp_opt_set_string() performs a talloc_strdup onto the appropriate
context internally.

It also updates the DEBUG messages for this function to the
appropriate new macro levels.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This function is not supposed to return any newly-allocated memory
directly. It was actually leaking the memory for krb5_servers if
krb5_kdcip was being used, though it was undetectable because it
was allocated on the provided memctx.

This patch removes the memctx parameter and allocates krb5_servers
temporarily on NULL and ensures that it is freed on all exit
conditions. It is not necessary to retain this memory, as
dp_opt_set_string() performs a talloc_strdup onto the appropriate
context internally.

It also updates the DEBUG messages for this function to the
appropriate new macro levels.
</pre>
</div>
</content>
</entry>
</feed>
