.Kerberos ticket policy now supports authentication indicators Authentication indicators are attached to Kerberos tickets based on which pre-authentication mechanism has been used to acquire the ticket: * `otp` for two-factor authentication (password + OTP) * `radius` for RADIUS authentication * `pkinit` for PKINIT, smart card or certificate authentication * `hardened` for hardened passwords (SPAKE or FAST) The Kerberos Distribution Center (KDC) can enforce policies such as service access control, maximum ticket lifetime, and maximum renewable age, on the service ticket requests which are based on the authentication indicators. With this enhancement, administrators can achieve finer control over service ticket issuance by requiring specific authentication indicators from a user's tickets.
Description Alexander Bokovoy 2019-11-27 20:25:22 UTC
Complete Authentication Indicator Kerberos ticket policy support by providing IPA CLI options.
For the authentication indicators 'otp', 'radius', 'pkinit', and 'hardened', allow specifying maximum ticket life and maximum renewable age in Kerberos ticket policy.
Related: https://pagure.io/freeipa/issue/8001
Related: https://pagure.io/freeipa/issue/8001

