#3041 SSSD IPA provider should request client principal canonicalization by default
Closed: Fixed Opened by mbabinsk.

The re-implementation of Kerberos principal handling during FreeIPA 4.4 development will enable proper support for user, host and service principal aliases and their canonicalization.

SSSD should reflect these changes by enforcing canonicalization flag in all TGT requests against FreeIPA KDCs similarly to SSSD-AD provider.


Sumit already has a WIP patch.

milestone: NEEDS_TRIAGE => SSSD 1.14 alpha
owner: somebody => sbose

I need to release the Alpha tarball today, moving to Beta.

milestone: SSSD 1.14 alpha => SSSD 1.14 beta

I need to release the Beta tarball today, moving to 1.14.0.

milestone: SSSD 1.14 beta => SSSD 1.14.0

Fields changed

patch: 0 => 1

  • master: e6b6b9fa79c67d7d2698bc7e33d2e2f6bb53d483

resolution: => fixed
status: new => closed

Fields changed

rhbz: => 0

Metadata Update from @mbabinsk:
- Issue assigned to sbose
- Issue set to the milestone: SSSD 1.14.0

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/4074

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata