#1883 Add a new option to disable the Kerberos locator plugin completely
Closed: Fixed Opened by jhrozek.

This is a short-term workaround until ticket #941 could be implemented fully.

Sumit proposed that we could add a new Kerberos provider option that would disable creating the kdcinfo files completely. Then the libkrb5 and by extension the sssd too would rely on servers from krb5.conf.


Fields changed

milestone: NEEDS_TRIAGE => SSSD 1.11 beta

Ticket has been cloned to Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=956723

rhbz: => [https://bugzilla.redhat.com/show_bug.cgi?id=956723 956723]

Fields changed

rhbz: [https://bugzilla.redhat.com/show_bug.cgi?id=956723 956723] => [https://bugzilla.redhat.com/show_bug.cgi?id=720688 720688] to [https://bugzilla.redhat.com/show_bug.cgi?id=720688 720688], [https://bugzilla.redhat.com/show_bug.cgi?id=869318 869318][https://bugzilla.redhat.com/show_bug.cgi?id=956723 956723]

Fields changed

rhbz: [https://bugzilla.redhat.com/show_bug.cgi?id=720688 720688] to [https://bugzilla.redhat.com/show_bug.cgi?id=720688 720688], [https://bugzilla.redhat.com/show_bug.cgi?id=869318 869318][https://bugzilla.redhat.com/show_bug.cgi?id=956723 956723] => [https://bugzilla.redhat.com/show_bug.cgi?id=720688 720688], [https://bugzilla.redhat.com/show_bug.cgi?id=869318 869318][https://bugzilla.redhat.com/show_bug.cgi?id=956723 956723]

Fields changed

milestone: SSSD 1.12 beta => SSSD 1.11 beta

Linked to Bugzilla bug: https://bugzilla.redhat.com/show_bug.cgi?id=951104 (RHEL RFE)

rhbz: [https://bugzilla.redhat.com/show_bug.cgi?id=720688 720688], [https://bugzilla.redhat.com/show_bug.cgi?id=869318 869318][https://bugzilla.redhat.com/show_bug.cgi?id=956723 956723] => [https://bugzilla.redhat.com/show_bug.cgi?id=720688 720688], [https://bugzilla.redhat.com/show_bug.cgi?id=869318 869318][https://bugzilla.redhat.com/show_bug.cgi?id=956723 956723], [https://bugzilla.redhat.com/show_bug.cgi?id=951104 951104]

Fields changed

changelog: =>
milestone: SSSD 1.11 beta => SSSD 1.10.0

I realized this option would require a string change, so I went ahead and wrote a patch for inclusion in 1.10 beta.

milestone: SSSD 1.10.0 => SSSD 1.10 beta
owner: somebody => jhrozek
patch: 0 => 1
status: new => assigned

Fields changed

changelog: => The enhancement introduces a new Kerberos provider option called krb5_use_kdcinfo. The option is true by default in all providers. When set to false, the SSSD will not create krb5 info files that the locator plugin consumes and the user would have to set up the Kerberos options manually in krb5.conf.

  • master: 14452cd066b51e32ca0ebad6c45ae909a1debe57

resolution: => fixed
status: assigned => closed

Metadata Update from @jhrozek:
- Issue assigned to jhrozek
- Issue set to the milestone: SSSD 1.10 beta

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/2925

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata