#9764 Protect *all* IPA service principals
Closed: fixed by frenaud. Opened by dhanina.

Some service principals used by IPA are not protected from accidental deletion.
This might cause issues if an administrator accidentally selects all principals and then deletes them.

It would be best to block accidental deletion of these by IPA commands and the WebUI with checks.

For instance. the dogtag and ipa-dnskeysyncd service principals are not protected from deletion, neither in the WebUI nor the CLI.


Metadata Update from @dhanina:
- Custom field rhbz adjusted to https://issues.redhat.com/browse/RHEL-4845

Metadata Update from @dhanina:
- Custom field on_review adjusted to https://github.com/freeipa/freeipa/pull/7733

master:

  • 14196891138e2f88b57d23120a4471496a3cccb6 Disallow removal of dogtag and ipa-dnskeysyncd services on IPA servers

ipa-4-12:

  • ac308ab8f5685465e755b4ba7e5d428fe38bea4d Disallow removal of dogtag and ipa-dnskeysyncd services on IPA servers

Metadata Update from @frenaud:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

Metadata