On Wed, 2009-11-18 at 11:31 -0500, Stephen Gallagher wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > On 11/16/2009 07:01 PM, Jakub Hrozek wrote: > > Per the discussion on sssd-devel list, nss_sss should not return a > > hardcoded value but this should rather be configurable to allow whatever > > the OS or distribution thinks is the best for the particular case. > > > > Fixes: #266 > > Nack. > > Simo and I discussed this a bit on IRC. As Brian says, it's more correct > to use "*" here, since the SSSD doesn't [currently] support shadow NSS > maps. Please make "*" the default. > > Also, I'm not sure that this shouldn't just be an undocumented option > (not visible in the manpages). In 99.9% of deployments, there should be > no need to change this value as long as we don't support shadow maps.
Right, I agree we want to leave this one undocumented for now. > Implementation looks fine, though. /me nods Simo. -- Simo Sorce * Red Hat, Inc * New York _______________________________________________ sssd-devel mailing list sssd-devel@lists.fedorahosted.org https://fedorahosted.org/mailman/listinfo/sssd-devel