diff options
author | Sumit Bose <sbose@redhat.com> | 2013-06-05 13:06:08 +0200 |
---|---|---|
committer | Jakub Hrozek <jhrozek@redhat.com> | 2013-06-06 23:58:57 +0200 |
commit | d153941864fe481399665be8fe583c9317194a99 (patch) | |
tree | 72a552e9807ce15e3f52b3816636dcc514c34493 /src/providers/ad | |
parent | 154e62fc712f4c994fbc684386302edca277a99a (diff) | |
download | sssd-d153941864fe481399665be8fe583c9317194a99.tar.gz sssd-d153941864fe481399665be8fe583c9317194a99.tar.bz2 sssd-d153941864fe481399665be8fe583c9317194a99.zip |
Always send the PAC to the PAC responder
Currently while doing a Kerberos based authentication the PAC was only
send to the PAC responder for principals from a different realm. This
reflects the FreeIPA use case of users from trusted domains.
This restriction does not make sense anymore when the data from the PAC
should be used for the AD provider as well. It also makes only limited
sense for the IPA use case, because when using GSSAPI the PAC of users
from the local IPA domain are already evaluated by the PAC responder.
Diffstat (limited to 'src/providers/ad')
0 files changed, 0 insertions, 0 deletions