summaryrefslogtreecommitdiffstats
path: root/README
diff options
context:
space:
mode:
authorSimo Sorce <simo@redhat.com>2015-06-19 17:11:42 -0400
committerSimo Sorce <simo@redhat.com>2015-06-20 17:38:49 -0400
commitdb999f985dc4357e32db6bcc893aa354d2595c98 (patch)
treec54f633c5e7f2f95e8cfe845261a4153abc6381d /README
parent79cb8bb8418cca0c408db3c79d78fa23d5e18564 (diff)
downloadmod_auth_gssapi-db999f985dc4357e32db6bcc893aa354d2595c98.tar.gz
mod_auth_gssapi-db999f985dc4357e32db6bcc893aa354d2595c98.tar.xz
mod_auth_gssapi-db999f985dc4357e32db6bcc893aa354d2595c98.zip
Add GssapiBasicAuthMech option
This option allows to set a different list of mechanisms to use with Basic Auth (Basic Auth must be explicitly enabled) than the list of mechs that are allowed with Negotiate or Raw GSSAPI Client authentication. Signed-off-by: Simo Sorce <simo@redhat.com>
Diffstat (limited to 'README')
-rw-r--r--README13
1 files changed, 13 insertions, 0 deletions
diff --git a/README b/README
index 87b1436..93a90b8 100644
--- a/README
+++ b/README
@@ -216,3 +216,16 @@ are allowed. The recognized mechanism names are: krb5, iakerb, ntlmssp
Example:
GssapiAllowedMech krb5
GssapiAllowedMech ntlmssp
+
+
+### GssapiBasicAuthMech
+
+List of mechanisms against which Basic Auth is attempted. This is useful to
+restrict the mechanisms that can be used to attaempt password auth.
+By default no mechanism is set, this means all locally available mechanisms
+are allowed, unless GssapiAllowedMech is set, in which case those are used.
+GssapiBasicAuthMech always takes precendence over GssapiAllowedMech.
+The recognized mechanism names are: krb5, iakerb, ntlmssp
+
+Example:
+ GssapiBasicAuthMech krb5