URL: https://github.com/SSSD/sssd/pull/813
Title: #813: SDAP: allow GSS-SPNEGO for LDAP SASL bind as well

sumit-bose commented:
"""
> In multi-domain AD environment, the subdomains still use GSSAPI even though I 
> specify SPNEGO for the joined domain. Specifying the mechanism for the 
> subdomain works fine, but I wonder if this is an oversight or intended for 
> some reason?

Thanks for checking, that is an oversight. I'll make sure the option is 
inherited by default. I think this would be expected behavior. If there really 
is a sub-domain where GSS-SPNEGO would not work it can be overwritten with a 
sub-domain option.
"""

See the full comment at 
https://github.com/SSSD/sssd/pull/813#issuecomment-493323551
_______________________________________________
sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org
To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/sssd-devel@lists.fedorahosted.org

Reply via email to