summaryrefslogtreecommitdiffstats
path: root/ipalib/plugins
diff options
context:
space:
mode:
authorAlexander Bokovoy <abokovoy@redhat.com>2013-09-28 21:49:57 +0200
committerMartin Kosek <mkosek@redhat.com>2013-10-04 10:25:31 +0200
commit749111e6c2dfbb288c864a6cd2f5ac228f30bec1 (patch)
treec791878bec8766d2e259cafff70591b893d56f1b /ipalib/plugins
parent0ab40cdf6b354e8b760f604f2f94cf3c2292217e (diff)
downloadfreeipa.git-749111e6c2dfbb288c864a6cd2f5ac228f30bec1.tar.gz
freeipa.git-749111e6c2dfbb288c864a6cd2f5ac228f30bec1.tar.xz
freeipa.git-749111e6c2dfbb288c864a6cd2f5ac228f30bec1.zip
KDC: implement transition check for trusted domains
When client principal requests for a ticket for a server principal and we have to perform transition, check that all three belong to either our domain or the domains we trust through forest trusts. In case all three realms (client, transition, and server) match trusted domains and our domain, issue permission to transition from client realm to server realm. Part of https://fedorahosted.org/freeipa/ticket/3909
Diffstat (limited to 'ipalib/plugins')
0 files changed, 0 insertions, 0 deletions