From ec93a5f5d677b006923cc3691e79735f9e40be33 Mon Sep 17 00:00:00 2001 From: Jakub Hrozek Date: Tue, 11 May 2010 17:51:55 +0200 Subject: SSSDConfigAPI fixes * add forgotten ldap_dns_service option * sync IPA and LDAP options (ldap_pwd_policy and ldap_tls_cacertdir) * ldap_uri is no longer mandatory for LDAP provider - the default is to use service discovery with no address set now. Ditto for krb5_kdcip and ipa_server --- src/config/etc/sssd.api.d/sssd-ipa.conf | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) (limited to 'src/config/etc/sssd.api.d/sssd-ipa.conf') diff --git a/src/config/etc/sssd.api.d/sssd-ipa.conf b/src/config/etc/sssd.api.d/sssd-ipa.conf index f71498cc2..60835d5df 100644 --- a/src/config/etc/sssd.api.d/sssd-ipa.conf +++ b/src/config/etc/sssd.api.d/sssd-ipa.conf @@ -1,6 +1,6 @@ [provider/ipa] ipa_domain = str, None, true -ipa_server = str, None, true +ipa_server = str, None, false ipa_hostname = str, None, false ldap_uri = str, None, false ldap_search_base = str, None, false @@ -12,6 +12,7 @@ ldap_network_timeout = int, None, false ldap_opt_timeout = int, None, false ldap_offline_timeout = int, None, false ldap_tls_cacert = str, None, false +ldap_tls_cacertdir = str, None, false ldap_tls_reqcert = str, None, false ldap_sasl_mech = str, None, false ldap_sasl_authid = str, None, false @@ -24,6 +25,8 @@ ldap_krb5_init_creds = bool, None, false ldap_entry_usn = str, None, false ldap_rootdse_last_usn = str, None, false ldap_referrals = bool, None, false +ldap_krb5_ticket_lifetime = int, None, false +ldap_dns_service_name = str, None, false [provider/ipa/id] ldap_search_timeout = int, None, false @@ -71,6 +74,7 @@ krb5_ccachedir = str, None, false krb5_ccname_template = str, None, false krb5_keytab = str, None, false krb5_validate = bool, None, false +ldap_pwd_policy = str, None, false [provider/ipa/access] -- cgit