Re: [Freeipa-users] k5login loophole even account is disabled on FreeIPA

2017-05-12 Thread Sumit Bose
On Fri, May 12, 2017 at 08:41:07AM +0200, Sumit Bose wrote: > On Fri, May 12, 2017 at 09:35:40AM +0300, Alexander Bokovoy wrote: > > On pe, 12 touko 2017, Thomas Lau wrote: > > > Folks, > > > > > > let's say I am user thomas, and user "temp1" already marked as "disabled" > > > on FreeIPA, but

Re: [Freeipa-users] k5login loophole even account is disabled on FreeIPA

2017-05-12 Thread Sumit Bose
On Fri, May 12, 2017 at 09:35:40AM +0300, Alexander Bokovoy wrote: > On pe, 12 touko 2017, Thomas Lau wrote: > > Folks, > > > > let's say I am user thomas, and user "temp1" already marked as "disabled" > > on FreeIPA, but tho...@domain.com is on /home/temp1/.k5login list, how come > > I could

Re: [Freeipa-users] k5login loophole even account is disabled on FreeIPA

2017-05-12 Thread Alexander Bokovoy
On pe, 12 touko 2017, Thomas Lau wrote: Folks, let's say I am user thomas, and user "temp1" already marked as "disabled" on FreeIPA, but tho...@domain.com is on /home/temp1/.k5login list, how come I could still "sudo su - temp1"? It seems skip the checking on FreeIPA even account is disabled.

[Freeipa-users] k5login loophole even account is disabled on FreeIPA

2017-05-12 Thread Thomas Lau
Folks, let's say I am user thomas, and user "temp1" already marked as "disabled" on FreeIPA, but tho...@domain.com is on /home/temp1/.k5login list, how come I could still "sudo su - temp1"? It seems skip the checking on FreeIPA even account is disabled. Did I miss any setting or it's normal? --