[Freeipa-devel] [PATCH] 455 Fallback to global policy in ipa-lockout plugin

Martin Kosek mkosek at redhat.com
Mon Feb 3 08:16:36 UTC 2014


On 01/31/2014 04:39 PM, Rob Crittenden wrote:
> Martin Kosek wrote:
>> On 01/30/2014 07:19 PM, Rob Crittenden wrote:
>>> Martin Kosek wrote:
>>>> krbPwdPolicyReference is no longer filled default users. Instead, plugins
>>>> fallback to hardcoded global policy reference.
>>>>
>>>> Fix ipa-lockout plugin to fallback to it instead of failing to apply
>>>> the policy.
>>>>
>>>> https://fedorahosted.org/freeipa/ticket/4085
>>>
>>> NACK.
>>>
>>> I think you should include the value of krberr in error messages (we aren't
>>> exactly consistent in this elsewhere in the code but we need to start
>>> somewhere).
>>>
>>> You check the wrong value after the krb5_get_default_realm() call.
>>>
>>> It is probably better to use slapi_ch_free_string() than free().
>>>
>>> At some point we'll need a common library where this sort of operation can be
>>> done.
>>>
>>> rob
>>
>> Good catch, sending updated patch.
>>
>> Martin
>>
> 
> ACK

Pushed to master, ipa-3-3.

Martin




More information about the Freeipa-devel mailing list