summaryrefslogtreecommitdiffstats
path: root/ipa-client
diff options
context:
space:
mode:
authorJan Cholasta <jcholast@redhat.com>2012-04-30 11:58:55 -0400
committerRob Crittenden <rcritten@redhat.com>2012-04-29 19:45:29 -0400
commit6321c5ba87ff916bfff7fa15d20cb6d1a18f20f0 (patch)
treedc461fcbf1e7cb66fa61908bb90179157a91c466 /ipa-client
parented99c51117fdc691c65ef9f366862bbe3a9f60ed (diff)
downloadfreeipa.git-6321c5ba87ff916bfff7fa15d20cb6d1a18f20f0.tar.gz
freeipa.git-6321c5ba87ff916bfff7fa15d20cb6d1a18f20f0.tar.xz
freeipa.git-6321c5ba87ff916bfff7fa15d20cb6d1a18f20f0.zip
Set the "KerberosAuthentication" option in sshd_config to "no" instead of "yes".
Setting it to "yes" causes sshd to handle kinits itself, bypassing SSSD. ticket 2689
Diffstat (limited to 'ipa-client')
-rwxr-xr-xipa-client/ipa-install/ipa-client-install2
1 files changed, 1 insertions, 1 deletions
diff --git a/ipa-client/ipa-install/ipa-client-install b/ipa-client/ipa-install/ipa-client-install
index 563e9c4d..7133cce0 100755
--- a/ipa-client/ipa-install/ipa-client-install
+++ b/ipa-client/ipa-install/ipa-client-install
@@ -878,7 +878,7 @@ def configure_ssh(fstore, ssh_dir, options):
fstore.backup_file(sshd_config)
changes = {
- 'KerberosAuthentication': 'yes',
+ 'KerberosAuthentication': 'no',
'GSSAPIAuthentication': 'yes',
'UsePAM': 'yes',
}