[Freeipa-devel] User life cycle: authentication and preserved attributes

2014-06-19 Thread thierry bordaz
Hello, Thanks for all you feedbacks and help about which attributes to preserved and how to limit authentication (simple and krb) to Active accounts, here are my understandings: 1. Staging (container: cn=staged users,cn=accounts,cn=provisioning,SUFFIX) plugins scoping

Re: [Freeipa-devel] User life cycle: authentication and preserved attributes

2014-06-19 Thread Simo Sorce
On Thu, 2014-06-19 at 15:32 +0200, thierry bordaz wrote: (those values must be active DN entries) userPassword/krb keys: copied from source entry if they exists Uhmm this may actually fail, as we prevent storing pre-hashed passwords :/ We'll

Re: [Freeipa-devel] User life cycle: authentication and preserved attributes

2014-06-19 Thread thierry bordaz
On 06/19/2014 03:41 PM, Simo Sorce wrote: On Thu, 2014-06-19 at 15:32 +0200, thierry bordaz wrote: (those values must be active DN entries) userPassword/krb keys: copied from source entry if they exists Uhmm this may actually fail, as we

Re: [Freeipa-devel] User life cycle: authentication and preserved attributes

2014-06-19 Thread Simo Sorce
On Thu, 2014-06-19 at 17:32 +0200, thierry bordaz wrote: On 06/19/2014 03:41 PM, Simo Sorce wrote: On Thu, 2014-06-19 at 15:32 +0200, thierry bordaz wrote: (those values must be active DN entries) userPassword/krb keys: copied from source entry if they