diff options
author | Jakub Hrozek <jhrozek@redhat.com> | 2012-11-19 17:36:55 +0100 |
---|---|---|
committer | Jakub Hrozek <jhrozek@redhat.com> | 2012-11-20 08:19:40 +0100 |
commit | e02bfe598789636ad2625809174069fab3a57705 (patch) | |
tree | ce9a74f60c07663eee768bf22daaabed5a265cec /src/python | |
parent | c7119467d0a0d9e24a887d43865bbbbe1d0ca680 (diff) | |
download | sssd-e02bfe598789636ad2625809174069fab3a57705.tar.gz sssd-e02bfe598789636ad2625809174069fab3a57705.tar.xz sssd-e02bfe598789636ad2625809174069fab3a57705.zip |
LDAP: Checking the principal should not be considered fatal
The check is too restrictive as the select_principal_from_keytab can
return something else than user requested right now.
Consider that user query for host/myserver@EXAMPLE.COM, then the
select_principal_from_keytab function will return "myserver" in primary and
"EXAMPLE.COM" in realm. So the caller needs to add logic to also break
down the principal to get rid of the host/ part. The heuristics would
simply get too complex.
select_principal_from_keytab will error out anyway if there's no
suitable principal at all.
Diffstat (limited to 'src/python')
0 files changed, 0 insertions, 0 deletions