The ipasam module uses the keytab_set extended LDAP operation which is deprecated and is planned to be removed.
The exop is used to detect if the LDAP server is really an IPA server and to create the cross-realm principal objects (krbtgt/DOM.A@DOM.B).
master:
ipa-4-3:
Metadata Update from @sbose: - Issue assigned to simo - Issue set to the milestone: FreeIPA 4.3.1
Login to comment on this ticket.