mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2025-02-25 18:55:28 -06:00
Set explicitly krbPwdPolicyReference attribute to all hosts (entries in cn=computers,cn=accounts), services (entries in cn=services,cn=accounts) and Kerberos services (entries in cn=$REALM,cn=kerberos). This is done using DS's CoS so no attributes are really added. The default policies effectively disable any enforcement or lockout for hosts and services. Since hosts and services use keytabs passwords enforcements doesn't make much sense. Also the lockout policy could be used for easy and cheap DoS. https://fedorahosted.org/freeipa/ticket/6561 Reviewed-By: Pavel Vomacka <pvomacka@redhat.com>
73 lines
1.7 KiB
Makefile
73 lines
1.7 KiB
Makefile
NULL =
|
|
|
|
appdir = $(IPA_DATA_DIR)/updates
|
|
app_DATA = \
|
|
05-pre_upgrade_plugins.update \
|
|
10-config.update \
|
|
10-enable-betxn.update \
|
|
10-selinuxusermap.update \
|
|
10-rootdse.update \
|
|
10-uniqueness.update \
|
|
10-schema_compat.update \
|
|
19-managed-entries.update \
|
|
20-aci.update \
|
|
20-dna.update \
|
|
20-host_nis_groups.update \
|
|
20-indices.update \
|
|
20-ipaservers_hostgroup.update \
|
|
20-nss_ldap.update \
|
|
20-replication.update \
|
|
20-sslciphers.update \
|
|
20-syncrepl.update \
|
|
20-user_private_groups.update \
|
|
20-winsync_index.update \
|
|
20-idoverride_index.update \
|
|
20-uuid.update \
|
|
20-default_password_policy.update \
|
|
21-replicas_container.update \
|
|
21-ca_renewal_container.update \
|
|
21-certstore_container.update \
|
|
25-referint.update \
|
|
30-provisioning.update \
|
|
30-s4u2proxy.update \
|
|
37-locations.update \
|
|
40-delegation.update \
|
|
40-realm_domains.update \
|
|
40-replication.update \
|
|
40-dns.update \
|
|
40-automember.update \
|
|
40-certprofile.update \
|
|
40-otp.update \
|
|
40-vault.update \
|
|
41-caacl.update \
|
|
41-lightweight-cas.update \
|
|
45-roles.update \
|
|
50-7_bit_check.update \
|
|
50-dogtag10-migration.update \
|
|
50-groupuuid.update \
|
|
50-hbacservice.update \
|
|
50-krbenctypes.update \
|
|
50-nis.update \
|
|
50-ipaconfig.update \
|
|
50-externalmembers.update \
|
|
55-pbacmemberof.update \
|
|
59-trusts-sysacount.update \
|
|
60-trusts.update \
|
|
61-trusts-s4u2proxy.update \
|
|
62-ranges.update \
|
|
71-idviews.update \
|
|
71-idviews-sasl-mapping.update \
|
|
72-domainlevels.update \
|
|
73-custodia.update \
|
|
73-winsync.update \
|
|
90-post_upgrade_plugins.update \
|
|
$(NULL)
|
|
|
|
EXTRA_DIST = \
|
|
$(app_DATA) \
|
|
$(NULL)
|
|
|
|
MAINTAINERCLEANFILES = \
|
|
*~ \
|
|
Makefile.in
|