Files
freeipa/ipaserver/plugins
Alexander Bokovoy 2ed5eca762 Reset per-indicator Kerberos policy
When 'ipa krbtpolicy-reset' is called, we need to reset all policy
settings, including per-indicator ones. Per-indicator policy uses
subtyped attributes (foo;bar), the current krbtpolicy-reset code does
not deal with those.

Add support for per-indicator policy reset. It is a bit tricky, as we
need to drop the values to defaults but avoid adding non-per-indicator
variants of the same attributes.

Add test to check that policy has been resetted by observing a new
Kerberos TGT for the user after its policy reset.

Fixes: https://pagure.io/freeipa/issue/8153

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
Reviewed-By: Christian Heimes <cheimes@redhat.com>
2019-12-18 14:16:33 +01:00
..
2010-12-20 17:19:53 -05:00
2017-03-27 19:08:26 +02:00
2019-06-18 10:36:24 +10:00
2018-01-09 07:53:28 +01:00
2019-10-21 18:01:32 +11:00
2019-10-21 18:01:32 +11:00
2019-03-28 00:21:00 +01:00
2019-09-27 09:38:32 +02:00
2019-09-27 09:38:32 +02:00
2019-11-11 09:31:14 +01:00
2018-01-09 07:53:28 +01:00
2018-10-05 12:06:19 +02:00
2019-09-27 09:38:32 +02:00
2018-07-14 12:04:19 +02:00
2018-07-14 12:04:19 +02:00
2019-03-28 17:57:58 +01:00
2017-09-08 15:42:07 +02:00
2019-10-21 18:01:32 +11:00
2019-03-28 00:21:00 +01:00