freeipa/install/updates
Rob Crittenden 00abd47de4 Enable 389-ds SSL host checking by defauilt
Enforce that the remote hostname matches the remote SSL server certificate
when 389-ds operates as an SSL client.

Also add an update file to turn this off for existing installations.

This also changes the way the ldapupdater modlist is generated to be more
like the framework. Single-value attributes are done as replacements
and there is a list of force-replacement attributes.

ticket 1069
2011-05-20 10:08:11 -04:00
..
10-60basev2.update Fix ORDERING in some attributetypes and remove other unnecessary elements. 2011-04-05 21:46:32 -04:00
10-config.update Enable 389-ds SSL host checking by defauilt 2011-05-20 10:08:11 -04:00
10-RFC2307bis.update Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
10-RFC4876.update Fix quoting to work with new csv handler in ldapupdate 2009-05-19 11:50:39 -06:00
20-aci.update Add aci to make managed netgroups immutable. 2011-02-18 15:29:51 -05:00
20-dna.update Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
20-indices.update Add memberHost and memberUser to default indexes 2011-04-08 11:00:24 -04:00
20-nss_ldap.update Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
20-replication.update Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
20-winsync_index.update Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
21-replicas_container.update Store list of non-master replicas in DIT and provide way to list them 2011-03-02 09:46:46 -05:00
30-policy.update Re-number some attributes to compress our usage to be contiguous 2010-05-27 10:50:49 -04:00
40-delegation.update Allow a client to enroll using principal when the host has a OTP 2011-03-30 10:03:44 -04:00
45-roles.update Use Sudo rather than SUDO as a label. 2011-03-01 16:48:35 -05:00
50-groupuuid.update The default groups we create should have ipaUniqueId set 2011-04-15 13:02:17 +02:00
50-lockout-policy.update Updated default Kerberos password policy 2011-02-16 22:28:08 -05:00
Makefile.am Enable 389-ds SSL host checking by defauilt 2011-05-20 10:08:11 -04:00
README Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00

The update files are sorted before being processed because there are
cases where order matters (such as getting schema added first, creating
parent entries, etc).

10 - 20: Schema
20 - 30: FDS Configuration, new indices
30 - 40: Structual elements of the DIT
40 - 50: Pre-loaded data