summaryrefslogtreecommitdiff
path: root/src/providers/krb5/krb5_access.c
AgeCommit message (Collapse)AuthorFilesLines
2013-09-23krb5: save canonical upn to sysdbSumit Bose1-2/+3
If the returned TGT contains a different user principal name (upn) than used in the request, i.e. the upn was canonicalized, we currently save it to sysdb into the same attribute where the upn coming from an LDAP server is stored as well. This means the canonical upn might be overwritten when the user data is re-read from the LDAP server. To avoid this this patch add a new attribute to sysdb where the canonical upn is stored and makes sure it is used when available. Fixes https://fedorahosted.org/sssd/ticket/2060
2013-06-27KRB5: guess UPN for subdomain usersJakub Hrozek1-1/+1
2013-01-21Remove sysdb as a be context structure memberSimo Sorce1-1/+1
The sysdb context is already available through the 'domain' structure.
2013-01-15Add domain argument to sysdb_get_user_attr()Simo Sorce1-2/+2
2012-12-04Fix tevent_req style for krb5_authSimo Sorce1-3/+3
No functionality changes, just make the code respect the tevent_req style and naming conventions and enhance readability by adding some helper functions.
2012-10-26Use find_or_guess_upn() where neededSumit Bose1-9/+7
2011-08-15sysdb refactoring: deleted domain variables in sysdb APIJan Zeleny1-2/+2
The patch also updates code using modified functions. Tests have also been adjusted.
2010-11-04Call krb5_child to check access permissionsSumit Bose1-4/+121
2010-11-04Add infrastructure for Kerberos access providerSumit Bose1-0/+91