On 08/17/2016 03:50 PM, Pavel Vomacka wrote:
On 08/17/2016 02:42 PM, Pavel Vomacka wrote:
On 08/11/2016 07:49 PM, Petr Vobornik wrote:
On 08/11/2016 07:21 PM, Martin Basti wrote:
It's prerequisite for https://fedorahosted.org/freeipa/ticket/5764
On 11.08.2016 18:57, Pavel Vomacka wrote:
On 08/11/2016 02:00 PM, Petr Vobornik wrote:
Here is patch with new checkbox. It is without ticket in commit
once we will have the ticket I will send another patch witch
On 08/11/2016 10:54 AM, Alexander Bokovoy wrote:
On Thu, 11 Aug 2016, Jan Cholasta wrote:
Right. The following patch adds ok_to_auth_as_delegate to the
On 4.8.2016 17:27, Jan Pazdziora wrote:
On Wed, Aug 03, 2016 at 10:29:52AM +0300, Alexander Bokovoy
That's because ok_as_delegate and ok_to_auth_as_delegate are
Got it. One thing I would correct, though, -- don't use
do support setting ok_as_delegate on the service principals
$ ipa service-mod --help |grep -A1 ok-as-delegate
Client credentials may be delegated
ipa service-mod --ok-as-delegate=True HTTP/$(hostname)
but that does not seem to have the same effect as
modprinc +ok_to_auth_as_delegate HTTP/ipa.example.test
-- obtaining the delegated certificated fails.
I haven't added any tickets to it yet.
This might deserve also nice Web UI checkbox similar to "Trusted for
delegation". CCing Pavel.
might use that.
Thank you, patch with updated commit message attached.
Attached patch adds checkbox also to host page.
Thank you, works as expected. ACK.
Manage your subscription for the Freeipa-devel mailing list:
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code