freeipa/ipaserver
Rob Crittenden 00abd47de4 Enable 389-ds SSL host checking by defauilt
Enforce that the remote hostname matches the remote SSL server certificate
when 389-ds operates as an SSL client.

Also add an update file to turn this off for existing installations.

This also changes the way the ldapupdater modlist is generated to be more
like the framework. Single-value attributes are done as replacements
and there is a list of force-replacement attributes.

ticket 1069
2011-05-20 10:08:11 -04:00
..
install Enable 389-ds SSL host checking by defauilt 2011-05-20 10:08:11 -04:00
plugins Return copy of config from ipa_get_config() 2011-05-13 13:09:24 -04:00
__init__.py Change FreeIPA license to GPLv3+ 2010-12-20 17:19:53 -05:00
conn.py Change FreeIPA license to GPLv3+ 2010-12-20 17:19:53 -05:00
ipaldap.py Enable 389-ds SSL host checking by defauilt 2011-05-20 10:08:11 -04:00
ipautil.py Change FreeIPA license to GPLv3+ 2010-12-20 17:19:53 -05:00
rpcserver.py Test for forwarded Kerberos credentials cache in wsgi code. 2011-05-18 09:35:04 +02:00