7a20fc6 Allow to specify Kerberos authz data type per user

2 files Authored by simo 8 years ago, Committed by mbasti 8 years ago,
    Allow to specify Kerberos authz data type per user
    
    Like for services setting the ipaKrbAuthzData attribute on a user object will
    allow us to control exactly what authz data is allowed for that user.
    Setting NONE would allow no authz data, while setting MS-PAC would allow only
    Active Directory compatible data.
    
    Signed-off-by: Simo Sorce <simo@redhat.com>
    
    Ticket: https://fedorahosted.org/freeipa/ticket/2579
    Reviewed-By: Alexander Bokovoy <abokovoy@redhat.com>
    
        
file modified
+1 -1