mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2024-12-24 08:00:02 -06:00
WebUI: cert login: Configure name of parameter used to pass username
Directive LookupUserByCertificateParamName tells mod_lookup_identity module the name of GET parameter that is used to provide username in case certificate is mapped to multiple user accounts. Without this directive login with certificate that's mapped to multiple users doesn't work. https://pagure.io/freeipa/issue/6860 Reviewed-By: Florence Blanc-Renaud <frenaud@redhat.com>
This commit is contained in:
parent
e560899cce
commit
157831a287
@ -117,6 +117,7 @@ Alias /ipa/session/cookie "/usr/share/ipa/gssapi.login"
|
|||||||
NSSVerifyClient require
|
NSSVerifyClient require
|
||||||
NSSUserName SSL_CLIENT_CERT
|
NSSUserName SSL_CLIENT_CERT
|
||||||
LookupUserByCertificate On
|
LookupUserByCertificate On
|
||||||
|
LookupUserByCertificateParamName "username"
|
||||||
WSGIProcessGroup ipa
|
WSGIProcessGroup ipa
|
||||||
WSGIApplicationGroup ipa
|
WSGIApplicationGroup ipa
|
||||||
GssapiImpersonate On
|
GssapiImpersonate On
|
||||||
|
Loading…
Reference in New Issue
Block a user