freeipa/ipa-client
Nathaniel McCallum 7ad9f5d3d5 Prefer TCP connections to UDP in krb5 clients
In general, TCP is a better fit for FreeIPA due to large packet sizes.

However, there is also a specific need for TCP when using OTP. If a UDP
packet is delivered to the server and the server takes longer to process
it than the client timeout (likely), the OTP value will be resent.
Unfortunately, this will cause failures or even lockouts. Switching to
TCP avoids this problem altogether.

https://fedorahosted.org/freeipa/ticket/4725

Reviewed-By: Martin Kosek <mkosek@redhat.com>
2014-12-08 10:56:06 +01:00
..
ipa-install Prefer TCP connections to UDP in krb5 clients 2014-12-08 10:56:06 +01:00
ipaclient Do not wait for new CA certificate to appear in LDAP in ipa-certupdate 2014-10-30 10:51:36 +01:00
man Add ipa-client-install switch --request-cert to request cert for the host 2014-10-16 19:11:52 +02:00
AUTHORS Fix build from autoconf patch import. 0001-01-01 00:00:00 +00:00
config.c Fix coverity issues in client CLI tools 2011-11-23 00:30:41 -05:00
configure.ac Use asn1c helpers to encode/decode the getkeytab control 2014-11-20 10:52:13 -05:00
ipa-client-common.c ipa-client: Use "ipa" as the package name for i18n 2013-07-19 12:26:28 +02:00
ipa-client-common.h include <stdint.h> for uintptr_t 2011-09-22 09:42:11 -04:00
ipa-client.spec.in Fix versioning for configure.ac and ipa-python/setup.py 2008-08-11 18:31:05 -04:00
ipa-getkeytab.c Use asn1c helpers to encode/decode the getkeytab control 2014-11-20 10:52:13 -05:00
ipa-join.c Fix unchecked return value in ipa-join 2014-11-25 08:23:24 +00:00
ipa-rmkeytab.c Use indexed format specifiers in i18n strings 2012-04-10 18:07:10 -04:00
Makefile.am Use asn1c helpers to encode/decode the getkeytab control 2014-11-20 10:52:13 -05:00
NEWS Fix build from autoconf patch import. 0001-01-01 00:00:00 +00:00
README Add a copy of the LICENSE and populate some README's 2008-01-23 10:30:18 -05:00
version.m4.in Fix versioning for configure.ac and ipa-python/setup.py 2008-08-11 18:31:05 -04:00

Code to be installed on any client that wants to be in an IPA domain.

Mostly consists of a tool for Linux systems that will help configure the
client so it will work properly in a kerberized environment.

It also includes several ways to configure Firefox to do single sign-on.

The two methods on the client side are:

1. globalsetup.sh. This modifies the global Firefox installation so that
   any profiles created will be pre-configured.

2. usersetup.sh. This will update a user's existing profile.

The downside of #1 is that an rpm -V will return a failure. It will also
need to be run with every update of Firefox.

One a profile contains the proper preferences it will be unaffected by
upgrades to Firefox. 

The downside of #2 is that every user would need to run this each time they
create a new profile.

There is a third, server-side method. See ipa-server/README for details.