#2080 When in IPA server mode, SSSD should map trusted forest subdomains to root domain realm
Closed: Fixed None Opened 7 years ago by abbra.

SSSD writes down domain/realm mapping information for Kerberos-enabled applications. This information should include mapping from subdomains' DNS domains to the trusted forest Kerberos realm. Right now only DNS domain of the forest root domain is mapped to the trusted forest Kerberos realm.

This is needed for IPA KDC to correctly issue referrals to the trusted forest root domain when handling access to services in the trusted forest subdomains.


Fields changed

milestone: NEEDS_TRIAGE => SSSD 1.11.1

Fields changed

owner: somebody => sbose
status: new => assigned

If a fix for #2093 is committed this ticket becomes invalid

This was fixed with the same fixes as #2093.

resolution: => fixed
status: assigned => closed

Metadata Update from @abbra:
- Issue assigned to sbose
- Issue set to the milestone: SSSD 1.11.1

3 years ago

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/3122

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Login to comment on this ticket.

Metadata