Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

trust-fetch-domains: contact forest DCs when fetching trust domain info #79

Closed
wants to merge 1 commit into from

Conversation

martbab
Copy link
Contributor

@martbab martbab commented Sep 13, 2016

The code should always contact forest root DCs when requesting trust domain
info. In the case of one-way or external trusts
com.redhat.idm.trust-fetch-domains helper is leveraged, otherwise forest
root domain is contacted directly through Samba using the credentials of HTTP
principal.

https://fedorahosted.org/freeipa/ticket/6328

The code should always contact forest root DCs when requesting trust domain
info. In the case of one-way or external trusts
`com.redhat.idm.trust-fetch-domains` helper is leveraged, otherwise forest
root domain is contacted directly through Samba using the credentials of HTTP
principal.

https://fedorahosted.org/freeipa/ticket/6328
@abbra
Copy link
Contributor

abbra commented Sep 14, 2016

LGTM. We discussed the placement of populate_remote_domain() but decided to keep it there.

@abbra abbra added the ack Pull Request approved, can be merged label Sep 14, 2016
@martbab martbab added the pushed Pull Request has already been pushed label Sep 14, 2016
@martbab martbab closed this Sep 14, 2016
@martbab martbab deleted the fix-trust-fetch-domains branch September 14, 2016 08:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ack Pull Request approved, can be merged pushed Pull Request has already been pushed
Projects
None yet
2 participants