[yast-commit] r63241 - in /trunk/ldap-client: VERSION package/yast2-ldap-client.changes src/Ldap.ycp
Author: jsuchome Date: Thu Jan 20 16:19:21 2011 New Revision: 63241 URL: http://svn.opensuse.org/viewcvs/yast?rev=63241&view=rev Log: - remove pam_krb5 when sssd is configured (fate#308902) - 2.20.7 Modified: trunk/ldap-client/VERSION trunk/ldap-client/package/yast2-ldap-client.changes trunk/ldap-client/src/Ldap.ycp Modified: trunk/ldap-client/VERSION URL: http://svn.opensuse.org/viewcvs/yast/trunk/ldap-client/VERSION?rev=63241&r1=63240&r2=63241&view=diff ============================================================================== --- trunk/ldap-client/VERSION (original) +++ trunk/ldap-client/VERSION Thu Jan 20 16:19:21 2011 @@ -1 +1 @@ -2.20.6 +2.20.7 Modified: trunk/ldap-client/package/yast2-ldap-client.changes URL: http://svn.opensuse.org/viewcvs/yast/trunk/ldap-client/package/yast2-ldap-client.changes?rev=63241&r1=63240&r2=63241&view=diff ============================================================================== --- trunk/ldap-client/package/yast2-ldap-client.changes (original) +++ trunk/ldap-client/package/yast2-ldap-client.changes Thu Jan 20 16:19:21 2011 @@ -1,4 +1,10 @@ ------------------------------------------------------------------- +Thu Jan 20 16:18:04 CET 2011 - jsuchome@suse.cz + +- remove pam_krb5 when sssd is configured (fate#308902) +- 2.20.7 + +------------------------------------------------------------------- Thu Jan 13 11:37:48 CET 2011 - jsuchome@suse.cz - pass certificate data to .ldap agent (bnc#662949) Modified: trunk/ldap-client/src/Ldap.ycp URL: http://svn.opensuse.org/viewcvs/yast/trunk/ldap-client/src/Ldap.ycp?rev=63241&r1=63240&r2=63241&view=diff ============================================================================== --- trunk/ldap-client/src/Ldap.ycp (original) +++ trunk/ldap-client/src/Ldap.ycp Thu Jan 20 16:19:21 2011 @@ -2049,6 +2049,7 @@ // In a mixed Kerberos/LDAP setup the following changes are needed in the [domain/default] section: if (Pam::Enabled("krb5")) { +// FIXME: do not test for pam, it may be already off... SCR::Write (add (domain, "auth_provider"), "krb5"); SCR::Write (add (domain, "chpass_provider"), "krb5"); /* @@ -2066,7 +2067,6 @@ if (is (e,map) && e != $[]) { map kerberos = (map) e; -y2internal ("kerberos export map: %1", kerberos); SCR::Write (add (domain, "krb5_realm"), kerberos["kerberos_client","default_domain"]:nil); SCR::Write (add (domain, "krb5_kdcip"), kerberos["kerberos_client","kdc_server"]:nil); } @@ -2581,6 +2581,11 @@ union (nsswitch["passwd"]:[], ["sss"])); Nsswitch::WriteDb ("group", (list<string>) union (nsswitch["group"]:[], ["sss"])); + if (Pam::Enabled("krb5")) + { + y2milestone ("configuring 'sss', so 'krb5' will be removed"); + Pam::Remove ("krb5"); + } } else { -- To unsubscribe, e-mail: yast-commit+unsubscribe@opensuse.org For additional commands, e-mail: yast-commit+help@opensuse.org
participants (1)
-
jsuchome@svn2.opensuse.org