[Freeipa-devel] Kerberos over HTTPS (KDC proxy)

Petr Spacek pspacek at redhat.com
Wed May 27 10:03:29 UTC 2015


On 26.5.2015 17:56, Christian Heimes wrote:
> On 2015-05-26 17:11, Nathaniel McCallum wrote:
>> I don't want to add code that: 1. is half-baked 2. we aren't committed
>> to supporting.
>> 
>> I'd rather land per-replica switches as a separate commit with 
>> everything polished and supportable.
> 
> Well then ... I'm going to remove the code for per-replica config and go 
> back to the global switch. Since I'm now familiar with the code, it's 
> easy for me to add it back, in case we need it again. :)

I do not see a *need* for the user interface to the per-replica switch. We
do not have such switch for any other optional component, like DNS.

IMHO it is perfectly fine to have only per-replica switch as we do for all
other components - and do not have user interface to the switch as we do not
have it for any other component.

It would be consistent, easy, and future proof.

-- 
Petr^2 Spacek




More information about the Freeipa-devel mailing list