Go to file
Nathaniel McCallum 7ad9f5d3d5 Prefer TCP connections to UDP in krb5 clients
In general, TCP is a better fit for FreeIPA due to large packet sizes.

However, there is also a specific need for TCP when using OTP. If a UDP
packet is delivered to the server and the server takes longer to process
it than the client timeout (likely), the OTP value will be resent.
Unfortunately, this will cause failures or even lockouts. Switching to
TCP avoids this problem altogether.

https://fedorahosted.org/freeipa/ticket/4725

Reviewed-By: Martin Kosek <mkosek@redhat.com>
2014-12-08 10:56:06 +01:00
.tx Update translations 2013-08-02 16:54:25 +02:00
asn1 Fix memory leak in GetKeytabControl asn1 code 2014-11-25 08:23:24 +00:00
checks Use /usr/bin/python2 2014-01-03 09:46:05 +01:00
contrib Set master_kdc and dns_lookup_kdc to true 2012-09-19 20:47:12 -04:00
daemons Make token auth and sync windows configurable 2014-12-05 13:42:19 +01:00
doc Remove the unused ipalib.frontend.Property class 2014-02-21 11:58:00 +01:00
init DNSSEC: add ipa dnssec daemons 2014-10-21 12:23:03 +02:00
install Prefer TCP connections to UDP in krb5 clients 2014-12-08 10:56:06 +01:00
ipa-client Prefer TCP connections to UDP in krb5 clients 2014-12-08 10:56:06 +01:00
ipalib hosts: Display assigned ID view by default in host-find and show commands 2014-12-05 15:55:38 +01:00
ipaplatform Do not restore SELinux settings that were not backed up 2014-11-19 15:47:45 +01:00
ipapython Unload P11_Helper object's library when it is finalized in ipap11helper 2014-11-25 08:23:24 +00:00
ipaserver certs: Fix incorrect flag handling in load_cacert 2014-12-02 14:44:42 +00:00
ipatests add --hosts and --hostgroup options to allow/retrieve keytab methods 2014-12-03 11:34:10 +00:00
util Fix unchecked return value in krb5 common utils 2014-11-25 08:23:24 +00:00
.gitignore Add asn1c generated code for keytab controls 2014-11-20 10:52:13 -05:00
.mailmap Update contributors 2014-10-20 08:18:09 +02:00
ACI.txt Make token auth and sync windows configurable 2014-12-05 13:42:19 +01:00
API.txt hosts: Display assigned ID view by default in host-find and show commands 2014-12-05 15:55:38 +01:00
autogen.sh build tweaks - use automake's foreign mode, avoid creating empty files to satisfy gnu mode - run autoreconf -f to ensure that everything matches 2010-11-29 11:39:55 -05:00
BUILD.txt Update README and BUILD 2014-02-12 14:04:07 +01:00
Contributors.txt Update contributors 2014-10-20 08:18:09 +02:00
COPYING Change FreeIPA license to GPLv3+ 2010-12-20 17:19:53 -05:00
freeipa.spec.in Use NSS protocol range API to set available TLS protocols 2014-11-24 13:09:44 +00:00
ipa Use /usr/bin/python2 2014-01-03 09:46:05 +01:00
ipa.1 Fix example usage in ipa man page. 2014-10-08 09:52:08 +02:00
lite-server.py Use /usr/bin/python2 2014-01-03 09:46:05 +01:00
make-doc Make an ipa-tests package 2013-06-17 19:22:50 +02:00
make-lint DNSNameParam parameter 2014-06-03 15:55:32 +02:00
make-test Switch make-test to pytest 2014-11-21 12:14:44 +01:00
makeaci makeaci: Use the DN where the ACI is stored, not the permission's DN 2014-07-07 14:42:52 +02:00
makeapi Use /usr/bin/python2 2014-01-03 09:46:05 +01:00
Makefile Use asn1c helpers to encode/decode the getkeytab control 2014-11-20 10:52:13 -05:00
MANIFEST.in Change FreeIPA license to GPLv3+ 2010-12-20 17:19:53 -05:00
pytest.ini Configure pytest to run doctests 2014-11-21 12:14:44 +01:00
README Update README and BUILD 2014-02-12 14:04:07 +01:00
setup-client.py Include the ipa command in client-only build 2014-09-23 20:28:47 +02:00
setup.py Include ipaplatform in client-only build 2014-09-23 20:28:47 +02:00
VERSION hosts: Display assigned ID view by default in host-find and show commands 2014-12-05 15:55:38 +01:00
version.m4.in Mass tree reorganization for IPAv2. To view previous history of files use: 2009-02-03 15:27:14 -05:00

                               IPA Server

  Overview
  --------

  FreeIPA allows Linux administrators to centrally manage identity,
  authentication and access control aspects of Linux and UNIX systems
  by providing simple to install and use command line and web based
  managment tools.
  FreeIPA is built on top of well known Open Source components and standard
  protocols with a very strong focus on ease of management and automation
  of installation and configuration tasks.
  FreeIPA can seamlessly integrate into an Active Directory environment via
  cross-realm Kerberos trust or user synchronization.

  Benefits
  --------

  FreeIPA:
  * Allows all your users to access all the machines with the same credentials
    and security settings
  * Allows users to access personal files transparently from any machine in
    an authenticated and secure way
  * Uses an advanced grouping mechanism to restrict network access to services
    and files only to specific users
  * Allows central management of security mechanisms like passwords,
    SSH Public Keys, SUDO rules, Keytabs, Access Control Rules
  * Enables delegation of selected administrative tasks to other power users
  * Integrates into Active Directory environments

  Components
  ----------

  The FreeIPA project provides unified installation and management
  tools for the following components:

  * LDAP Server - based on the 389 project (LDAP)
    http://directory.fedoraproject.org/wiki/Main_Page

  * KDC - based on MIT Kerberos implementation
    http://k5wiki.kerberos.org/wiki/Main_Page

  * PKI based on Dogtag project
    http://pki.fedoraproject.org/wiki/PKI_Main_Page

  * Samba libraries for Active Directory integration
    http://www.samba.org/

  * DNS Server based on BIND and the Bind-DynDB-LDAP plugin
    https://www.isc.org/software/bind
    https://fedorahosted.org/bind-dyndb-ldap


  Project Website
  ---------------

  Releases, announcements and other information can be found on the IPA
  server project page at <http://www.freeipa.org/>.

  Documentation
  -------------

  The most up-to-date documentation can be found at
  <http://freeipa.org/page/Documentation>.

  Quick Start
  -----------

  To get started quickly, start here:
  <http://www.freeipa.org/page/Quick_Start_Guide>

  Licensing
  ---------

  Please see the file called COPYING.

  Contacts
  --------

     * If you want to be informed about new code releases, bug fixes,
       security fixes, general news and information about the IPA server
       subscribe to the freeipa-announce mailing list at
       <https://www.redhat.com/mailman/listinfo/freeipa-interest/>.

     * If you have a bug report please submit it at:
       <https://bugzilla.redhat.com>

     * If you want to participate in actively developing IPA please
       subscribe to the freeipa-devel mailing list at
       <https://www.redhat.com/mailman/listinfo/freeipa-devel/> or join
       us in IRC at irc://irc.freenode.net/freeipa