Bug 786206 - Document how to modify browser config to remove ticket delegation
Summary: Document how to modify browser config to remove ticket delegation
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: doc-Identity_Management_Guide
Version: 6.3
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: rc
: 6.3
Assignee: Deon Ballard
QA Contact: ecs-bugs
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2012-01-31 17:39 UTC by Dmitri Pal
Modified: 2012-06-29 15:13 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2012-06-29 15:13:51 UTC
Target Upstream Version:


Attachments (Terms of Use)

Description Dmitri Pal 2012-01-31 17:39:11 UTC
This bug is created as a clone of upstream ticket:
https://fedorahosted.org/freeipa/ticket/2310

With IPA 2.2 we will be using a feature of the KDC called S4U2Proxy (services for user to proxy). We won't need users to delegated their TGT to IPA anymore.

This means that people who have already configured their web browser to delegate their TGT can unset this. It won't cause problems if it is set but it is essentially sharing your full identity with a remote server so not doing so is safer.

To do this the user will need to go to the URL about:config

Search for delegation

Select the value network.negotiate-auth.delegation-uris and clear out the IPA domain (.example.com or example.com) and click Ok.

That's it. No need to restart the browser.

This will only work against 2.2+.


Note You need to log in before you can comment on or make changes to this bug.