summaryrefslogtreecommitdiffstats
path: root/ipapython/errors.py
diff options
context:
space:
mode:
authorPavel Vomacka <pvomacka@redhat.com>2017-03-14 17:44:01 +0100
committerMartin Basti <mbasti@redhat.com>2017-03-14 18:56:03 +0100
commitf4cd61f3011877fc9cc2a809438059b07362b0aa (patch)
treecee5983939bd6ba7e3dab2e0b54ece5a916b5a75 /ipapython/errors.py
parent2c194d793cd588d595c5ff639fbf5dac93e50e23 (diff)
downloadfreeipa-f4cd61f3011877fc9cc2a809438059b07362b0aa.tar.gz
freeipa-f4cd61f3011877fc9cc2a809438059b07362b0aa.tar.xz
freeipa-f4cd61f3011877fc9cc2a809438059b07362b0aa.zip
Remove allow_constrained_delegation from gssproxy.conf
The Apache process must not allowed to use constrained delegation to contact services because it is already allowed to impersonate users to itself. Allowing it to perform constrained delegation would let it impersonate any user against the LDAP service without authentication. https://pagure.io/freeipa/issue/6225 Reviewed-By: Simo Sorce <ssorce@redhat.com>
Diffstat (limited to 'ipapython/errors.py')
0 files changed, 0 insertions, 0 deletions