On Mon, Jul 26, 2021 at 10:43 AM Assaf Morami <[email protected]>
wrote:

> Hi James, thanks for the swift response.
>
> Is it possible to turn off certificate matching against AD, and just use
> the username while taking the certificate directly from the smart card?
>

But matching by username is still matching. You need to match based on
something in the cert, otherwise everybody will be able to present any
smart card, right?

Is this username embedded into the certificate? In the subject maybe?




>
> On my setup it's not feasible to attach certificates to user on AD, that's
> why I'm looking for a workaround.
>
> Thanks,
> Assaf.
> _______________________________________________
> sssd-users mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
> Fedora Code of Conduct:
> https://docs.fedoraproject.org/en-US/project/code-of-conduct/
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives:
> https://lists.fedorahosted.org/archives/list/[email protected]
> Do not reply to spam on the list, report it:
> https://pagure.io/fedora-infrastructure
>
_______________________________________________
sssd-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam on the list, report it: 
https://pagure.io/fedora-infrastructure

Reply via email to