diff options
author | Jan Cholasta <jcholast@redhat.com> | 2012-04-30 11:58:55 -0400 |
---|---|---|
committer | Rob Crittenden <rcritten@redhat.com> | 2012-04-29 19:45:29 -0400 |
commit | 6321c5ba87ff916bfff7fa15d20cb6d1a18f20f0 (patch) | |
tree | dc461fcbf1e7cb66fa61908bb90179157a91c466 | |
parent | ed99c51117fdc691c65ef9f366862bbe3a9f60ed (diff) | |
download | freeipa-6321c5ba87ff916bfff7fa15d20cb6d1a18f20f0.tar.gz freeipa-6321c5ba87ff916bfff7fa15d20cb6d1a18f20f0.tar.xz freeipa-6321c5ba87ff916bfff7fa15d20cb6d1a18f20f0.zip |
Set the "KerberosAuthentication" option in sshd_config to "no" instead of "yes".
Setting it to "yes" causes sshd to handle kinits itself, bypassing SSSD.
ticket 2689
-rwxr-xr-x | ipa-client/ipa-install/ipa-client-install | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/ipa-client/ipa-install/ipa-client-install b/ipa-client/ipa-install/ipa-client-install index 563e9c4df..7133cce04 100755 --- a/ipa-client/ipa-install/ipa-client-install +++ b/ipa-client/ipa-install/ipa-client-install @@ -878,7 +878,7 @@ def configure_ssh(fstore, ssh_dir, options): fstore.backup_file(sshd_config) changes = { - 'KerberosAuthentication': 'yes', + 'KerberosAuthentication': 'no', 'GSSAPIAuthentication': 'yes', 'UsePAM': 'yes', } |