Bug 1303683
| Summary: | dogtag should support GSSAPI based auth in conjuction with FreeIPA | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Matthew Harmsen <mharmsen> |
| Component: | pki-core | Assignee: | Fraser Tweedale <ftweedal> |
| Status: | CLOSED ERRATA | QA Contact: | Asha Akkiangady <aakkiang> |
| Severity: | unspecified | Docs Contact: | Marc Muehlfeld <mmuehlfe> |
| Priority: | medium | ||
| Version: | 7.3 | CC: | alee, arubin, cheimes, edewata, ftweedal, ksiddiqu, mkosek, nkinder, nsoman, pvoborni |
| Target Milestone: | rc | ||
| Target Release: | 7.4 | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | pki-core-10.4.1-3.el7 | Doc Type: | Enhancement |
| Doc Text: |
Certificate System now supports externally authenticated users
Previously, you had to create users and roles in Certificate System. With this enhancement, you can now configure Certificate System to admit users authenticated by an external identity provider. Additionally, you can use realm-specific authorization access control lists (ACLs). As a result, it is no longer necessary to create users in Certificate System.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2017-08-01 22:46:01 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 1399979 | ||
|
Description
Matthew Harmsen
2016-02-01 16:32:41 UTC
Per CS Bug/Ticket Triage held 04/19/2016: RHEL 7.4 Confirmed with Fraser. RHCS 9.2 PRD item 1.3 is medium priority. Changes have been pushed to master; moving bug to POST for inclusion in RHEL 7.4 (beta). This ticket is closely related to https://bugzilla.redhat.com/show_bug.cgi?id=1388622. This is not a feature we are actively using in IPA or elsewhere at the moment, but we wanted to land the changes as early as possible. IPA will make use of them in a future release. Therefore, it is quite involved to test. I recommend moving on to other bugs, while I work on a blog post explaining these features and provides examples that can be used to verify the new functionality. I'd also recommend the same QE contact verify both bugs. This feature is not tested. RHCS subsystems installation and functional tests looks good. Marking it verified sanity only. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2017:2110 |