Go to file
Simo Sorce 7a20fc671b Allow to specify Kerberos authz data type per user
Like for services setting the ipaKrbAuthzData attribute on a user object will
allow us to control exactly what authz data is allowed for that user.
Setting NONE would allow no authz data, while setting MS-PAC would allow only
Active Directory compatible data.

Signed-off-by: Simo Sorce <simo@redhat.com>

Ticket: https://fedorahosted.org/freeipa/ticket/2579
Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com>
2016-03-09 19:00:43 +01:00
asn1 CONFIGURE: Replace obsolete macros 2016-03-08 20:02:27 +01:00
checks Remove unused imports 2015-12-23 07:59:22 +01:00
client CONFIGURE: Replace obsolete macros 2016-03-08 20:02:27 +01:00
contrib Modernize mod_nss's cipher suites 2016-02-11 10:44:29 +01:00
daemons Allow to specify Kerberos authz data type per user 2016-03-09 19:00:43 +01:00
doc Use print_function future definition wherever print() is used 2016-01-20 11:59:21 +01:00
init Add ipa-custodia service 2015-10-15 14:24:33 +02:00
install Allow to specify Kerberos authz data type per user 2016-03-09 19:00:43 +01:00
ipaclient ipadiscovery: Decode to unicode in ipacheckldap(), get_ipa_basedn() 2016-03-03 10:31:55 +01:00
ipalib Allow admins to disable preauth for SPNs. 2016-03-08 18:48:40 +01:00
ipaplatform Move freeipa certmonger helpers to libexecdir. 2016-02-26 08:29:44 +01:00
ipapython ipapython.sysrestore: Use str methods instead of functions from the string module 2016-03-03 10:31:55 +01:00
ipaserver Configure 389ds with "default" cipher suite 2016-03-09 10:04:58 +01:00
ipatests test_cert_plugin: use only first part of the hostname to construct short name 2016-03-08 20:22:55 +01:00
util Add compatibility function for older libkrb5 2015-05-30 12:24:15 -04:00
.gitignore Split ipa-client/ into ipaclient/ (Python library) and client/ (C, scripts) 2016-01-27 12:09:02 +01:00
.mailmap Update Contributors.txt 2015-12-02 12:31:54 +01:00
ACI.txt fix permission: Read Replication Agreements 2016-02-25 14:30:01 +01:00
API.txt Allow admins to disable preauth for SPNs. 2016-03-08 18:48:40 +01:00
autogen.sh build tweaks - use automake's foreign mode, avoid creating empty files to satisfy gnu mode - run autoreconf -f to ensure that everything matches 2010-11-29 11:39:55 -05:00
BUILD.txt Update Build instructions 2015-12-03 16:23:10 +01:00
Contributors.txt Update Contributors.txt 2015-12-02 12:31:54 +01:00
COPYING Change FreeIPA license to GPLv3+ 2010-12-20 17:19:53 -05:00
COPYING.openssl Add a clear OpenSSL exception. 2015-02-23 16:25:54 +01:00
freeipa.spec.in configure DNA plugin shared config entries to allow connection with GSSAPI 2016-03-02 16:43:17 +01:00
ipa Remove unused imports 2015-12-23 07:59:22 +01:00
ipa.1 Fix example usage in ipa man page. 2014-10-08 09:52:08 +02:00
lite-server.py Port from python-krbV to python-gssapi 2015-08-26 09:41:36 +02:00
make-doc Make an ipa-tests package 2013-06-17 19:22:50 +02:00
make-test Switch make-test to pytest 2014-11-21 12:14:44 +01:00
makeaci Remove unused imports 2015-12-23 07:59:22 +01:00
makeapi Use the print function 2015-09-01 11:42:01 +02:00
Makefile make lint: use config file and plugin for pylint 2016-02-11 11:06:39 +01:00
MANIFEST.in Change FreeIPA license to GPLv3+ 2010-12-20 17:19:53 -05:00
pylint_plugins.py Pylint: add missing attributes of errors to definitions 2016-02-25 13:54:20 +01:00
pylintrc Pylint: enable parallelism 2016-03-07 12:33:21 +01:00
pytest.ini Configure pytest to run doctests 2014-11-21 12:14:44 +01:00
README Update README and BUILD 2014-02-12 14:04:07 +01:00
setup.py Package ipapython, ipalib, ipaplatform, ipatests for Python 3 2015-12-17 10:52:57 +01:00
VERSION Allow admins to disable preauth for SPNs. 2016-03-08 18:48:40 +01:00
version.m4.in Mass tree reorganization for IPAv2. To view previous history of files use: 2009-02-03 15:27:14 -05:00
zanata.xml l10n: Add configuration file for Zanata 2015-07-07 12:07:15 +02:00

                               IPA Server

  Overview
  --------

  FreeIPA allows Linux administrators to centrally manage identity,
  authentication and access control aspects of Linux and UNIX systems
  by providing simple to install and use command line and web based
  managment tools.
  FreeIPA is built on top of well known Open Source components and standard
  protocols with a very strong focus on ease of management and automation
  of installation and configuration tasks.
  FreeIPA can seamlessly integrate into an Active Directory environment via
  cross-realm Kerberos trust or user synchronization.

  Benefits
  --------

  FreeIPA:
  * Allows all your users to access all the machines with the same credentials
    and security settings
  * Allows users to access personal files transparently from any machine in
    an authenticated and secure way
  * Uses an advanced grouping mechanism to restrict network access to services
    and files only to specific users
  * Allows central management of security mechanisms like passwords,
    SSH Public Keys, SUDO rules, Keytabs, Access Control Rules
  * Enables delegation of selected administrative tasks to other power users
  * Integrates into Active Directory environments

  Components
  ----------

  The FreeIPA project provides unified installation and management
  tools for the following components:

  * LDAP Server - based on the 389 project (LDAP)
    http://directory.fedoraproject.org/wiki/Main_Page

  * KDC - based on MIT Kerberos implementation
    http://k5wiki.kerberos.org/wiki/Main_Page

  * PKI based on Dogtag project
    http://pki.fedoraproject.org/wiki/PKI_Main_Page

  * Samba libraries for Active Directory integration
    http://www.samba.org/

  * DNS Server based on BIND and the Bind-DynDB-LDAP plugin
    https://www.isc.org/software/bind
    https://fedorahosted.org/bind-dyndb-ldap


  Project Website
  ---------------

  Releases, announcements and other information can be found on the IPA
  server project page at <http://www.freeipa.org/>.

  Documentation
  -------------

  The most up-to-date documentation can be found at
  <http://freeipa.org/page/Documentation>.

  Quick Start
  -----------

  To get started quickly, start here:
  <http://www.freeipa.org/page/Quick_Start_Guide>

  Licensing
  ---------

  Please see the file called COPYING.

  Contacts
  --------

     * If you want to be informed about new code releases, bug fixes,
       security fixes, general news and information about the IPA server
       subscribe to the freeipa-announce mailing list at
       <https://www.redhat.com/mailman/listinfo/freeipa-interest/>.

     * If you have a bug report please submit it at:
       <https://bugzilla.redhat.com>

     * If you want to participate in actively developing IPA please
       subscribe to the freeipa-devel mailing list at
       <https://www.redhat.com/mailman/listinfo/freeipa-devel/> or join
       us in IRC at irc://irc.freenode.net/freeipa