[SSSD] [sssd PR#225][+Changes requested] SECRETS: Apply separate quotas for cn=secrets and cn=kcm

2017-06-27 Thread jhrozek
URL: https://github.com/SSSD/sssd/pull/225 Title: #225: SECRETS: Apply separate quotas for cn=secrets and cn=kcm Label: +Changes requested ___ sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org To unsubscribe send an email to sssd-devel-le...

[SSSD] [sssd PR#225][comment] SECRETS: Apply separate quotas for cn=secrets and cn=kcm

2017-06-27 Thread jhrozek
URL: https://github.com/SSSD/sssd/pull/225 Title: #225: SECRETS: Apply separate quotas for cn=secrets and cn=kcm jhrozek commented: """ On Tue, Jun 27, 2017 at 09:02:56AM -0700, lslebodn wrote: > @jhrozek > Do you plan to fix nspr problem also for functions `sss_password_encrypt` and > `sss_pa

[SSSD] [sssd PR#225][comment] SECRETS: Apply separate quotas for cn=secrets and cn=kcm

2017-06-27 Thread lslebodn
URL: https://github.com/SSSD/sssd/pull/225 Title: #225: SECRETS: Apply separate quotas for cn=secrets and cn=kcm lslebodn commented: """ @jhrozek Do you plan to fix nspr problem also for functions `sss_password_encrypt` and `sss_password_decrypt`? """ See the full comment at https://github.c

[SSSD] Re: Evaluating HBAC rules for other hosts

2017-06-27 Thread Jakub Hrozek
On Tue, Jun 27, 2017 at 11:40:37AM +0100, Howard Johnson wrote: > In Ipsilon, we recently (OK, about a year ago) added an authorisation stack. > This allows us to control, Ipsilon-side, which users are permitted to log > into which service providers. Our authorisation plugin functions are > curren

[SSSD] Evaluating HBAC rules for other hosts

2017-06-27 Thread Howard Johnson
In Ipsilon, we recently (OK, about a year ago) added an authorisation stack. This allows us to control, Ipsilon-side, which users are permitted to log into which service providers. Our authorisation plugin functions are currently fairly limited, basically using user group membership to contro