summaryrefslogtreecommitdiffstats
path: root/ipapython/errors.py
diff options
context:
space:
mode:
authorDavid Kupka <dkupka@redhat.com>2016-09-29 15:59:34 +0200
committerDavid Kupka <dkupka@redhat.com>2016-12-14 17:46:12 +0100
commit6f1d927467e7907fd1991f88388d96c67c9bff61 (patch)
tree3d93711c22f741d7326851093c4f766393a7a8bd /ipapython/errors.py
parentd841a79dc104521f736469eff7154c2f4266082b (diff)
downloadfreeipa-6f1d927467e7907fd1991f88388d96c67c9bff61.tar.gz
freeipa-6f1d927467e7907fd1991f88388d96c67c9bff61.tar.xz
freeipa-6f1d927467e7907fd1991f88388d96c67c9bff61.zip
password policy: Add explicit default password policy for hosts and services
Set explicitly krbPwdPolicyReference attribute to all hosts (entries in cn=computers,cn=accounts), services (entries in cn=services,cn=accounts) and Kerberos services (entries in cn=$REALM,cn=kerberos). This is done using DS's CoS so no attributes are really added. The default policies effectively disable any enforcement or lockout for hosts and services. Since hosts and services use keytabs passwords enforcements doesn't make much sense. Also the lockout policy could be used for easy and cheap DoS. https://fedorahosted.org/freeipa/ticket/6561 Reviewed-By: Pavel Vomacka <pvomacka@redhat.com>
Diffstat (limited to 'ipapython/errors.py')
0 files changed, 0 insertions, 0 deletions