[Freeipa-devel] [PATCH] 455 Fallback to global policy in ipa-lockout plugin

Martin Kosek mkosek at redhat.com
Tue Feb 4 10:33:13 UTC 2014


On 02/04/2014 10:27 AM, Petr Viktorin wrote:
> On 02/03/2014 09:16 AM, Martin Kosek wrote:
>> On 01/31/2014 04:39 PM, Rob Crittenden wrote:
>>> Martin Kosek wrote:
>>>> On 01/30/2014 07:19 PM, Rob Crittenden wrote:
>>>>> Martin Kosek wrote:
>>>>>> krbPwdPolicyReference is no longer filled default users. Instead, plugins
>>>>>> fallback to hardcoded global policy reference.
>>>>>>
>>>>>> Fix ipa-lockout plugin to fallback to it instead of failing to apply
>>>>>> the policy.
>>>>>>
>>>>>> https://fedorahosted.org/freeipa/ticket/4085
>>>>>
>>>>> NACK.
>>>>>
>>>>> I think you should include the value of krberr in error messages (we aren't
>>>>> exactly consistent in this elsewhere in the code but we need to start
>>>>> somewhere).
>>>>>
>>>>> You check the wrong value after the krb5_get_default_realm() call.
>>>>>
>>>>> It is probably better to use slapi_ch_free_string() than free().
>>>>>
>>>>> At some point we'll need a common library where this sort of operation can be
>>>>> done.
>>>>>
>>>>> rob
>>>>
>>>> Good catch, sending updated patch.
>>>>
>>>> Martin
>>>>
>>>
>>> ACK
>>
>> Pushed to master, ipa-3-3.
>>
>> Martin
> 
> I'm unable to install IPA on f20 with this patch. Does it work for you?
> 

Same here. I unfortunately tested this only on running IPA. See my patch 456,
it fixes it.

Martin




More information about the Freeipa-devel mailing list