URL: https://github.com/SSSD/sssd/pull/813 Title: #813: SDAP: allow GSS-SPNEGO for LDAP SASL bind as well
sumit-bose commented: """ > In multi-domain AD environment, the subdomains still use GSSAPI even though I > specify SPNEGO for the joined domain. Specifying the mechanism for the > subdomain works fine, but I wonder if this is an oversight or intended for > some reason? Thanks for checking, that is an oversight. I'll make sure the option is inherited by default. I think this would be expected behavior. If there really is a sub-domain where GSS-SPNEGO would not work it can be overwritten with a sub-domain option. """ See the full comment at https://github.com/SSSD/sssd/pull/813#issuecomment-493323551
_______________________________________________ sssd-devel mailing list -- sssd-devel@lists.fedorahosted.org To unsubscribe send an email to sssd-devel-le...@lists.fedorahosted.org Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/sssd-devel@lists.fedorahosted.org