#618 Create krb5 access provider
Closed: Fixed Opened by sgallagh.

Currently, we behave differently from pam_krb5.so during the pam_account phase. When pam_account calls into SSSD, we should have a kerberos access provider that invokes krb5_kuserok() with the user's principal.

This way, if the local system provides a .k5login file that would restrict access from this user, they are appropriately denied.

This should probably happen only when dealing with remote users, not those on the local console.


Fields changed

milestone: NEEDS_TRIAGE => SSSD 1.5.0

Fields changed

owner: somebody => sbose

Fixed by:
- 1e29e68388c2e9c5da9cb0afe997bc1b4e6933be
- 0bbe2065770968c70fd305da4f6eda1a360a3f1b
- fab9c6a75eaf09e4f5440f4bb530c26009b0ffc7
- c3593efe68ddee16b810944e5dc808740b14942d
- b87233035e26cee919dcf46adaec29ba7fdaa51e
- e7a4ea98c6751a8c3d8405ca31481006f29b901e

fixedin: => 1.5.0
resolution: => fixed
status: new => closed

Fields changed

rhbz: => 0

Metadata Update from @sgallagh:
- Issue assigned to sbose
- Issue set to the milestone: SSSD 1.5.0

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/1660

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata