#5336 [RFE] Create a server side switch that would force only secure authentication methods
Closed: wontfix by rcritten. Opened by dpal.

Some of the older non tunnelled authentication methods like a time stamp are susceptible to the dictionary attacks. More details on the issue can be read in RFC4120 chapter 10 paragraph 6.

This can be addressed by using FAST tunnel or anonymous pkinit. Upcoming SPAKE solution also addressed the issue algorithmically.

To be able to use Kerberos in environments with tightened security policies there needs to be an easy way to only allow SPAKE, FAST or pkinit based authentication and not allow other older less secure methods.

This RFE asks for:
- Collaboration with Kerberos upstream to provide such knob
- Have a way to make this change in IPA in a manageable way (UI/CLI or some simple documented procedure)


Metadata Update from @dpal:
- Issue assigned to someone
- Issue set to the milestone: Future Releases

Thank you taking time to submit this request for FreeIPA. Unfortunately this bug was not given priority and the team lacks the capacity to work on it at this time.

Given that we are unable to fulfil this request I am closing the issue as wontfix. To request re-consideration of this decision please reopen this issue and provide additional technical details about its importance to you.

Metadata Update from @rcritten:
- Issue close_status updated to: wontfix
- Issue status updated to: Closed (was: Open)

Metadata