summaryrefslogtreecommitdiff
path: root/src/providers/krb5/krb5_init.c
AgeCommit message (Collapse)AuthorFilesLines
2013-07-23KRB5: Do not send PAC in server modeJakub Hrozek1-0/+1
The krb5 child contacts the PAC responder for any user except for the IPA native users if the PAC is configured. This works fine for the general case but the ipa_server_mode is a special one. The PAC responder is there, but since in the server mode we should be operating as AD provider default, the PAC shouldn't be analyzed either in this case.
2013-06-10A new option krb5_use_kdcinfoJakub Hrozek1-5/+12
https://fedorahosted.org/sssd/ticket/1883 The patch introduces a new Kerberos provider option called krb5_use_kdcinfo. The option is true by default in all providers. When set to false, the SSSD will not create krb5 info files that the locator plugin consumes and the user would have to set up the Kerberos options manually in krb5.conf
2013-01-02let krb5_backup_kpasswd failover workPavel Březina1-2/+2
https://fedorahosted.org/sssd/ticket/1735
2012-08-01Primary server support: new options in krb5 providerJan Zeleny1-4/+13
This patch adds support for new config options krb5_backup_server and krb5_backup_kpasswd. The description of this option's functionality is included in man page in one of previous patches.
2012-08-01Primary server support: krb5 adaptationJan Zeleny1-2/+2
This patch adds support for the primary server functionality into krb5 provider. No backup servers are added at the moment, just the basic support is in place.
2012-07-06KRB5: Create a common init routine for krb5_child optionsStephen Gallagher1-53/+6
This will reduce code duplication between the krb5, ipa and ad providers
2012-06-20Move some debug lines to new debug log levelsStef Walter1-1/+1
* These are common lines of debug output when starting up sssd https://bugzilla.redhat.com/show_bug.cgi?id=811113
2011-12-19Move child_common routines to utilStephen Gallagher1-1/+1
2011-05-04Do not leak pcre contextJakub Hrozek1-0/+12
2010-12-07Add support for FAST in krb5 providerSumit Bose1-1/+1
2010-12-03Add support for automatic Kerberos ticket renewalSumit Bose1-0/+10
2010-11-04Add infrastructure for Kerberos access providerSumit Bose1-0/+7
2010-11-04Store krb5 auth context for other targetsSumit Bose1-1/+2
2010-10-19Option krb5_server is now used to store a list of KDCs instead of krb5_kdcip.Jan Zeleny1-1/+1
For the time being, if krb5_server is not found, still falls back to krb5_kdcip with a warning. If both options are present in config file, krb5_server has a higher priority. Fixes: #543
2010-05-27Refactor krb5 SIGTERM handler installationSumit Bose1-14/+3
2010-05-27Add callback to remove krb5 info files when going offlineSumit Bose1-0/+7
2010-05-26Add support for delayed kinit if offlineSumit Bose1-0/+8
If the configuration option krb5_store_password_if_offline is set to true and the backend is offline the plain text user password is stored and used to request a TGT if the backend becomes online. If available the Linux kernel key retention service is used.
2010-05-16Properly set up SIGCHLD handlersStephen Gallagher1-1/+0
Instead of having all-purpose SIGCHLD handlers that try to catch every occurrence, we instead create a per-PID handler. This will allow us to specify callbacks to occur when certain children exit.
2010-05-07Use service discovery in backendsJakub Hrozek1-4/+4
Integrate the failover improvements with our back ends. The DNS domain used in the SRV query is always the SSSD domain name. Please note that this patch changes the default value of ldap_uri from "ldap://localhost" to "NULL" in order to use service discovery with no server set.
2010-05-07Clean up kdcinfo and kpasswdinfo files when exitingStephen Gallagher1-2/+10
2010-03-12Add krb5_kpasswd optionSumit Bose1-3/+18
2010-03-11Add expandable sequences to krb5_ccachedirSumit Bose1-0/+12
As with krb5_ccname_template sequences like %u can be used in the krb5_ccachedir parameter which are expanded at runtime. If the directory does not exist, it will be created. Depending on the used sequences it is created as a public or private directory.
2010-02-18Rename server/ directory to src/Stephen Gallagher1-0/+152
Also update BUILD.txt