summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorStephen Gallagher <sgallagh@redhat.com>2011-09-08 15:04:32 -0400
committerStephen Gallagher <sgallagh@redhat.com>2011-09-20 10:43:46 -0400
commit82faa5293d37a850455f8cd71e59c6e5ae954ea6 (patch)
treee293d1e920e20610fc543aba41bdd075bde09f15
parent1effb8547cb8bc53887b3733fce729f8f3c24bd6 (diff)
downloadsssd_unused-82faa5293d37a850455f8cd71e59c6e5ae954ea6.tar.gz
sssd_unused-82faa5293d37a850455f8cd71e59c6e5ae954ea6.tar.xz
sssd_unused-82faa5293d37a850455f8cd71e59c6e5ae954ea6.zip
MAN: Add more information about internal credential storage
-rw-r--r--src/man/sssd-krb5.5.xml5
-rw-r--r--src/man/sssd.conf.5.xml4
2 files changed, 8 insertions, 1 deletions
diff --git a/src/man/sssd-krb5.5.xml b/src/man/sssd-krb5.5.xml
index 04523c06..529bf24f 100644
--- a/src/man/sssd-krb5.5.xml
+++ b/src/man/sssd-krb5.5.xml
@@ -260,7 +260,10 @@
</para>
<para>
Please note that this feature currently only
- available on a Linux platform.
+ available on a Linux platform. Passwords stored in
+ this way are kept in plaintext in the kernel
+ keyring and are potentially accessible by the root
+ user (with difficulty).
</para>
<para>
Default: false
diff --git a/src/man/sssd.conf.5.xml b/src/man/sssd.conf.5.xml
index f5119433..bed06eb5 100644
--- a/src/man/sssd.conf.5.xml
+++ b/src/man/sssd.conf.5.xml
@@ -697,6 +697,10 @@
in the local LDB cache
</para>
<para>
+ User credentials are stored in a SHA512 hash, not
+ in plaintext
+ </para>
+ <para>
Default: FALSE
</para>
</listitem>