[Freeipa-devel] [PATCH] 0065 Use ldapi with krb5kdc

Simo Sorce ssorce at redhat.com
Thu Jan 20 00:11:45 UTC 2011


Long ago we decided to use the ldapi socket to let the KDC access the
ldap data in order to avoid comunication over the network (even if it
is 127.0.0.1).

This patch finally implements that. Although beware that this patch
will need you to either create custom policy or to set selinux in
permissive mode until the new policy lands in fedora land.

Bugs have been opened and I think the policy has already landed in
rawhide.

Simo.

-- 
Simo Sorce * Red Hat, Inc * New York
-------------- next part --------------
A non-text attachment was scrubbed...
Name: freeipa-simo-0065-Make-krb5kdc-use-the-ldapi-socket-to-talk-to-dirsrv.patch
Type: text/x-patch
Size: 1868 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20110119/94eebd88/attachment.bin>


More information about the Freeipa-devel mailing list