#5495 ipasam: replace deprecated keytab_set exop
Closed: Fixed Opened by sbose.

The ipasam module uses the keytab_set extended LDAP operation which is deprecated and is planned to be removed.

The exop is used to detect if the LDAP server is really an IPA server and to create the cross-realm principal objects (krbtgt/DOM.A@DOM.B).


master:

  • e011b376a5d071492bf3adfae26e4d61e2face07 Improve keytab code to select the right principal.
  • f9ed0b6ff8bf7e59de5450200d9fc5ad6e05299c Convert ipa-sam to use the new getkeytab control

ipa-4-3:

  • 108ec950db413732714ccf5f1dd5c7205674d30c Improve keytab code to select the right principal.
  • 7e09456d8b80eabb87bb2cf595904b5cc740af8e Convert ipa-sam to use the new getkeytab control

Metadata Update from @sbose:
- Issue assigned to simo
- Issue set to the milestone: FreeIPA 4.3.1

Metadata