Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-49437

Unconditionally add MS-PAC to global config

    • idm-DL1-8100020241119115741.823393f5
    • None
    • Important
    • 1
    • rhel-sst-idm-ipa
    • ssg_idm
    • 5
    • QE ack, Dev ack
    • False
    • Hide

      None

      Show
      None
    • No
    • 2024-Q4-Alpha-S5
    • Unspecified Release Note Type - Unknown
    • None

      To enable PAC generation, the "MS-PAC" value has to be set for "ipaKrbAuthzData" in "cn=ipaConfig,cn=etc,$SUFFIX".

      However, the LDIF file is using the "addifnew" instruction, which is skipped in case the attribute already exists. This is not the behaviour we want. "MS-PAC" should be added unconditionally, especially now on RHEL 8 where the PAC is required by the Bronze-Bit attack detection mechanism. Not supporting the PAC breaks the IPA API on this RHEL version.

              jrische@redhat.com Julien Rische
              jrische@redhat.com Julien Rische
              Julien Rische Julien Rische
              Sudhir Menon Sudhir Menon
              Votes:
              0 Vote for this issue
              Watchers:
              9 Start watching this issue

                Created:
                Updated:
                Resolved: