summaryrefslogtreecommitdiffstats
path: root/ipalib/plugins/baseldap.py
diff options
context:
space:
mode:
authorSimo Sorce <simo@redhat.com>2012-11-19 12:26:04 -0500
committerRob Crittenden <rcritten@redhat.com>2012-11-30 16:30:10 -0500
commit5269458f552380759c86018cd1f30b64761be92e (patch)
tree3dd2d9544450c81c940540378bbb8073a5c7d9c1 /ipalib/plugins/baseldap.py
parentc8d522bc98fb11be92529259e7a2072796012910 (diff)
downloadfreeipa.git-5269458f552380759c86018cd1f30b64761be92e.tar.gz
freeipa.git-5269458f552380759c86018cd1f30b64761be92e.tar.xz
freeipa.git-5269458f552380759c86018cd1f30b64761be92e.zip
MS-PAC: Special case NFS services
The current Linux NFS server is severely limited when it comes to handling kerberos tickets. Bsically any ticket bigger than 2k will cause it to fail authentication due to kernel->userspace upcall interface restrictions. Until we have additional support in IPA to indivdually mark principals to opt out of getting PACs attached we always prevent PACs from being attached to TGTs or Tickets where NFS is involved.
Diffstat (limited to 'ipalib/plugins/baseldap.py')
0 files changed, 0 insertions, 0 deletions