[Freeipa-devel] [PATCH] 455 Fallback to global policy in ipa-lockout plugin

Rob Crittenden rcritten at redhat.com
Fri Jan 31 15:39:05 UTC 2014


Martin Kosek wrote:
> On 01/30/2014 07:19 PM, Rob Crittenden wrote:
>> Martin Kosek wrote:
>>> krbPwdPolicyReference is no longer filled default users. Instead, plugins
>>> fallback to hardcoded global policy reference.
>>>
>>> Fix ipa-lockout plugin to fallback to it instead of failing to apply
>>> the policy.
>>>
>>> https://fedorahosted.org/freeipa/ticket/4085
>>
>> NACK.
>>
>> I think you should include the value of krberr in error messages (we aren't
>> exactly consistent in this elsewhere in the code but we need to start somewhere).
>>
>> You check the wrong value after the krb5_get_default_realm() call.
>>
>> It is probably better to use slapi_ch_free_string() than free().
>>
>> At some point we'll need a common library where this sort of operation can be
>> done.
>>
>> rob
>
> Good catch, sending updated patch.
>
> Martin
>

ACK




More information about the Freeipa-devel mailing list