Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-49437

Unconditionally add MS-PAC to global config

    • None
    • None
    • sst_idm_ipa
    • ssg_idm
    • 5
    • False
    • Hide

      None

      Show
      None
    • No
    • None
    • None
    • None
    • Unspecified Release Note Type - Unknown
    • None

      To enable PAC generation, the "MS-PAC" value has to be set for "ipaKrbAuthzData" in "cn=ipaConfig,cn=etc,$SUFFIX".

      However, the LDIF file is using the "addifnew" instruction, which is skipped in case the attribute already exists. This is not the behaviour we want. "MS-PAC" should be added unconditionally, especially now on RHEL 8 where the PAC is required by the Bronze-Bit attack detection mechanism. Not supporting the PAC breaks the IPA API on this RHEL version.

            jrische@redhat.com Julien Rische
            jrische@redhat.com Julien Rische
            Julien Rische Julien Rische
            Michal Polovka Michal Polovka
            Votes:
            0 Vote for this issue
            Watchers:
            7 Start watching this issue

              Created:
              Updated: