#999 Add a Kerberos provider option to set krb5_get_init_creds_opt_set_forwardable
Closed: Invalid Opened by jhrozek.

This would be analogous to kinit's -f: request forwardable tickets.


Fields changed

milestone: NEEDS_TRIAGE => SSSD 1.8.0
priority: major => minor

Fields changed

type: defect => enhancement

Fields changed

blockedby: =>
blocking: =>
milestone: SSSD 1.8.0 => SSSD 1.9.0

Linked to Bugzilla bug: https://bugzilla.redhat.com/show_bug.cgi?id=740848

Fields changed

milestone: SSSD 1.9.0 => SSSD Kerberos improvements

Fields changed

rhbz: => 0

I've spent some more time thinking about this. While it's an easy knob to provide, and I initially was in favor of it, I can't come up with any scenarios where I'd want to explicitly set SSSD's behavior to be different from the rest of the system, which heeds the default value for this setting as set (or not) in /etc/krb5.conf. It's less work for the administrator to just have to change it once, in /etc/krb5.conf, so I'm going to mark this as won't-fix.

cc: => nalin
feature_milestone: =>
proposed_priority: => Undefined
resolution: => wontfix
status: new => closed

Metadata Update from @jhrozek:
- Issue set to the milestone: SSSD Kerberos Improvements Feature

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/2041

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata