#881 [RFE] support the equivalent of kinit -C in sssd as an option
Closed: Duplicate None Opened 12 years ago by simo.

In order to allow a kinit using a principal alias the client needs to explicitly set a flag. This is done in kinit by passing the -C flag.
We should allow sssd to optional pass that flag to the KDC as well on user login.


This ticket is requesting the addition of a configuration option to enable principal aliases.

This option will allow to use aliases to get tickets.
May allow someone to use "administrator" as the name when the server has it on file as "Administrator".

in general I'd like to use krb flags that allows the server to do canonicalization, so that if we decide to support aliases to ignore variations in the case of characters in the fqdn (like for the keytab sssd uses) the clients will not prevent the KDC from doing that.

Fields changed

milestone: NEEDS_TRIAGE => SSSD 1.7.0

I am not sure we need it for trusts work. If not I would prefer to push it out.

milestone: SSSD 1.8.0 => SSSD 1.9.0

Fields changed

blockedby: =>
blocking: =>
milestone: SSSD 1.9.0 => SSSD Kerberos improvemens
rhbz: =>

Fields changed

rhbz: => 0

Fields changed

feature_milestone: =>
proposed_priority: => Core

Fields changed

rhbz: 0 => todo
summary: RFE: support the equivalent of kinit -C in sssd as an option => [RFE] support the equivalent of kinit -C in sssd as an option
type: defect => enhancement

Moving all the features planned for 1.10 release into 1.10 beta.

milestone: SSSD Kerberos Improvements Feature => SSSD 1.10 beta

Fields changed

priority: major => critical

Fields changed

design: =>
design_review: => 0
fedora_test_page: =>
selected: => Not need

Moving tickets that are not a priority for SSSD 1.10 into the next release.

milestone: SSSD 1.10 beta => SSSD 1.11 beta

It was done as a part of some other ticket some time ago. Closing.

changelog: =>
milestone: SSSD 1.12 beta => SSSD 1.9.0
resolution: => duplicate
review: => 0
rhbz: todo => 0
status: new => closed

Metadata Update from @simo:
- Issue set to the milestone: SSSD 1.9.0

7 years ago

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/1923

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Login to comment on this ticket.

Metadata