Nathaniel McCallum
abb63ed9d1
Add HOTP support
...
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com>
2014-02-21 10:26:02 +01:00
Jan Cholasta
97c1c95f20
Convert remaining update code to LDAPEntry API.
2014-01-24 20:29:31 +01:00
Petr Viktorin
c813b8fbd3
Do not fail upgrade if the global anonymous read ACI is not found
...
This helps forward compatibility: the anon ACI is scheduled for removal.
https://fedorahosted.org/freeipa/ticket/3956
2013-10-04 15:41:56 +02:00
Nathaniel McCallum
4bbbc11029
Permit reads to ipatokenRadiusProxyUser objects
...
This fixes an outstanding permissions issue from the OTP work.
https://fedorahosted.org/freeipa/ticket/3693
2013-07-11 12:39:27 +03:00
Nathaniel McCallum
cb68935435
Add IPA OTP schema and ACLs
...
This commit adds schema support for two factor authentication via
OTP devices, including RADIUS or TOTP. This schema will be used
by future patches which will enable two factor authentication
directly.
https://fedorahosted.org/freeipa/ticket/3365
http://freeipa.org/page/V3/OTP
2013-05-17 09:30:51 +02:00
Rob Crittenden
d5966bde80
Update anonymous access ACI to protect secret attributes.
...
Update anonymous access ACI so that no users besides Trust Admins
users can read AD Trust key attributes (ipaNTTrustAuthOutgoing,
ipaNTTrustAuthIncoming). The change is applied both for updated
IPA servers and new installations.
2013-01-23 15:31:48 -05:00