[Freeipa-devel] [PATCH] 994 set nsslapd-minssf-exclude-rootdse

Martin Kosek mkosek at redhat.com
Mon Mar 26 12:29:21 UTC 2012


On Thu, 2012-03-22 at 17:21 -0400, Rob Crittenden wrote:
> If minssf is set in configuration and this is not set then clients won't 
> be able to detect the available namingContexts, defaultNamingContext, 
> capabilities, etc.
> 
> This was requested by the SSSD team.
> 
> rob

ACK. Works fine - RootDSE is not accessible even with lower SSF than
minSSF.

Martin




More information about the Freeipa-devel mailing list