freeipa/install/updates
Rob Crittenden 453a19fcac First pass at enforcing certificates be requested from same host
We want to only allow a machine to request a certificate for itself, not for
other machines. I've added a new taksgroup which will allow this.

The requesting IP is resolved and compared to the subject of the CSR to
determine if they are the same host. The same is done with the service
principal. Subject alt names are not queried yet.

This does not yet grant machines actual permission to request certificates
yet, that is still limited to the taskgroup request_certs.
2009-10-21 03:22:44 -06:00
..
10-RFC2307bis.update Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
10-RFC4876.update Fix quoting to work with new csv handler in ldapupdate 2009-05-19 11:50:39 -06:00
20-dna.update Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
20-indices.update Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
20-nss_ldap.update Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
20-replication.update Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
20-winsync_index.update Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
30-automount.update Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
30-groupofhosts.update Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
30-netgroups.update Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
30-policy.update Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
30-rolegroup.update Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
30-taskgroup.update Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
40-delegation.update First pass at enforcing certificates be requested from same host 2009-10-21 03:22:44 -06:00
Makefile.am Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00
README Name update files so they can be easily sorted. 2009-03-25 11:03:07 -04:00

The update files are sorted before being processed because there are
cases where order matters (such as getting schema added first, creating
parent entries, etc).

10 - 20: Schema
20 - 30: FDS Configuration, new indices
30 - 40: Structual elements of the DIT
40 - 50: Pre-loaded data