1e0dfe1 Use the right attribute with ipapwd_entry_checks for MagicRegen

1 file Authored by sbose 10 years ago, Committed by mkosek 10 years ago,
    Use the right attribute with ipapwd_entry_checks for MagicRegen
    
    There is a special mode to set the ipaNTHash attribute if a RC4 Kerberos
    key is available for the corresponding user. This is typically triggered
    by samba via the ipa_sam passdb plugin. The principal used by samba to
    connect to the IPA directory server has the right to modify ipaNTHash
    but no other password attribute. This means that the current check on
    the userPassword attribute is too strict for this case and leads to a
    failure of the whole operation.
    
    With this patch the access right on ipaNTHash are checked if no other
    password operations are requested.