[Freeipa-devel] [PATCH] 0138, 0141: ipa-kdb fixes

Martin Kosek mkosek at redhat.com
Wed Feb 26 07:53:15 UTC 2014


On 02/25/2014 07:59 PM, Simo Sorce wrote:
> On Tue, 2014-02-25 at 20:58 +0200, Alexander Bokovoy wrote:
>> Resending patch 0138 together with another case Simo found out today:
>> when authdata flag is cleared by admin for the service principal, we'll
>> get NULL client database entry. In such case we have to bail out.
> 
> The patches look correct code-flow-wise to me.
> 
> So tentative ack pending testing.
> 
> Simo.
> 

Just checking - are we ok performance wise? If we for example add one
additional LDAP search for every Kerberos authentication, it may increase the
load on our LDAP server.

Martin




More information about the Freeipa-devel mailing list