-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
On 02/21/2011 11:45 AM, Stephen Gallagher wrote:
On 02/21/2011 11:34 AM, Stephen Gallagher wrote:
It is possible to set up FreeIPA servers where the Kerberos realm differs from the IPA domain name. We need to allow setting the krb5_realm explicitly to handle this.
Withdrawing this patch. I just realized it's incomplete.
Un-withdrawing this patch (re-attaching for posterity).
I thought we were not honoring krb5_realm elsewhere, because we were just doing dp_get_option(KRB5_REALM), but I discovered that ipa_get_id_options() and ipa_get_auth_options() forcibly sets these values to be correct.
So the only piece that was incorrect was ipa_service_init() (which only uses the realm for writing the krb5info file.
- -- Stephen Gallagher RHCE 804006346421761
Delivering value year after year. Red Hat ranks #1 in value among software vendors. http://www.redhat.com/promo/vendor/