diff options
author | Nathaniel McCallum <npmccallum@redhat.com> | 2014-05-08 11:06:16 -0400 |
---|---|---|
committer | Martin Kosek <mkosek@redhat.com> | 2014-06-25 12:55:02 +0200 |
commit | 5baa9413177c624be8398f6a23614e2ce0bdbba3 (patch) | |
tree | 01cb98fcbea98bc15e61486b69897c2f86733aac /install/updates | |
parent | bd1df14bd6f7f94de9044294cae045549019273f (diff) | |
download | freeipa-5baa9413177c624be8398f6a23614e2ce0bdbba3.tar.gz freeipa-5baa9413177c624be8398f6a23614e2ce0bdbba3.tar.xz freeipa-5baa9413177c624be8398f6a23614e2ce0bdbba3.zip |
Implement OTP token importing
This patch adds support for importing tokens using RFC 6030 key container
files. This includes decryption support. For sysadmin sanity, any tokens
which fail to add will be written to the output file for examination. The
main use case here is where a small subset of a large set of tokens fails
to validate or add. Using the output file, the sysadmin can attempt to
recover these specific tokens.
This code is implemented as a server-side script. However, it doesn't
actually need to run on the server. This was done because importing is an
odd fit for the IPA command framework:
1. We need to write an output file.
2. The operation may be long-running (thousands of tokens).
3. Only admins need to perform this task and it only happens infrequently.
https://fedorahosted.org/freeipa/ticket/4261
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com>
Diffstat (limited to 'install/updates')
0 files changed, 0 insertions, 0 deletions