[Freeipa-devel] [PATCH] #333 plugin to change kerberos principal name when user is renamed

Simo Sorce ssorce at redhat.com
Mon Oct 25 15:45:45 UTC 2010


On Mon, 25 Oct 2010 11:42:09 -0400
Nalin Dahyabhai <nalin at redhat.com> wrote:

> On Mon, Oct 25, 2010 at 10:53:19AM -0400, Rob Crittenden wrote:
> > Simo Sorce wrote:
> > >Can you do a modrdn modification on a compat plugin entry ?
> > 
> > Well, right, I don't know :-) And if not, what error would be
> > raised and do/should we catch it?
> 
> You should get an insufficient-access (0.17 and earlier) or
> unwilling-to-perform (0.18 and later) error result.

And I guess this happens quite early.
The ipa_modrdn plugin is invoked only as a post op, so if an error is
thrown earlier I think it is not even invoked.

Simo.

-- 
Simo Sorce * Red Hat, Inc * New York




More information about the Freeipa-devel mailing list