URL: https://github.com/freeipa/freeipa/pull/1294 Author: abbra Title: #1294: Trust avoid mitkrb trust Action: opened
PR body: """ Quite often users choose wrong type of trust on Active Directory side when setting up a trust to freeIPA. The trust type supported by freeIPA is just a normal forest trust to another Active Directory. However, some people follow old internet recipes that force using a trust to MIT Kerberos realm.
This is a wrong type of trust. Unfortunately, when someone used MIT Kerberos realm trust, there is no way to programmatically remote the trust from freeIPA side. As result, we have to detect such situation and report an error.
To do proper reporting, we need reuse some constants and trust type names we use in IPA CLI/Web UI. These common components were moved to a separate ipaserver/dcerpc_common.py module that is imported by both ipaserver/plugins/trust.py and ipaserver/dcerpc.py.
Fixes https://pagure.io/freeipa/issue/7264 """
To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/1294/head:pr1294 git checkout pr1294
URL: https://github.com/freeipa/freeipa/pull/1294 Author: abbra Title: #1294: Trust avoid mitkrb trust Action: closed
To pull the PR as Git branch: git remote add ghfreeipa https://github.com/freeipa/freeipa git fetch ghfreeipa pull/1294/head:pr1294 git checkout pr1294
freeipa-devel@lists.fedorahosted.org