diff options
| author | David Kupka <dkupka@redhat.com> | 2017-03-09 12:28:26 +0100 |
|---|---|---|
| committer | Martin Basti <mbasti@redhat.com> | 2017-03-15 10:34:44 +0100 |
| commit | 70889d4d5e7e2bd65ab1d4a28e5eda4a51c9b0c0 (patch) | |
| tree | b736646c23dafe13d7187f21b47d333535d939d8 /Makefile.python.am | |
| parent | e20ad9c251d9118959e501cd49997662de8cdbfc (diff) | |
| download | freeipa-70889d4d5e7e2bd65ab1d4a28e5eda4a51c9b0c0.tar.gz freeipa-70889d4d5e7e2bd65ab1d4a28e5eda4a51c9b0c0.tar.xz freeipa-70889d4d5e7e2bd65ab1d4a28e5eda4a51c9b0c0.zip | |
rpcserver: x509_login: Handle unsuccessful certificate login gracefully
When mod_lookup_identity is unable to match user by certificate (and username)
it unsets http request's user. mod_auth_gssapi is then unable to get Kerberos
ticket and doesn't set KRB5CCNAME environment variable.
x509_login.__call__ now returns 401 in such case to indicate that request was
not authenticated.
https://pagure.io/freeipa/issue/6225
Reviewed-By: Florence Blanc-Renaud <frenaud@redhat.com>
Diffstat (limited to 'Makefile.python.am')
0 files changed, 0 insertions, 0 deletions
