[Freeipa-devel] [PATCH] 0001 Added new authentication method

Rob Crittenden rcritten at redhat.com
Mon Aug 1 15:17:12 UTC 2016


Tibor Dudlak wrote:
> Hi,
>
> I have added few lines to code to make optional login with personal
> certificate (or with smartcard) possible. Some ui changes has to be
> made. It is not cosher but it definitely work.
>
> Thank you, Tibor
>

What about the Apache changes to require a certificate in 
/ipa/session/login_x509?

Does/will this only support a specially crafted certificate subject?

How/where does the UI get a Kerberos ticket for the user?

rob




More information about the Freeipa-devel mailing list