-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
On 02/23/2011 06:18 PM, Sumit Bose wrote:
On Wed, Feb 23, 2011 at 05:59:13PM +0100, Jakub Hrozek wrote: On 02/23/2011 05:33 PM, Sumit Bose wrote:
On Wed, Feb 23, 2011 at 05:24:20PM +0100, Jakub Hrozek wrote: https://fedorahosted.org/sssd/ticket/807
NACK, please use the "new" option from 'Add krb5_realm to the basic IPA options'
bye, Sumit
See, that's what I get for not reading today's patches.
New one attached. I also explicitly set IPA_KRB5_REALM for cases where we use the uppercase domain as realm value so it's always available.
Patch looks good, would you mind to add a paragraph to the man page of the IPA provider which explains the special role of krb5_realm for the IPA provider?
bye, Sumit
Of course. A new patch is attached. I did one more modification - the values of SDAP_KRB5_REALM and KRB5_REALM for ipa_id and ipa_auth respectively now default to IPA_KRB5_REALM, not IPA_DOMAIN.toupper(). It should technically be the same, but I think the new way is more consistent.
Jakub