#3510 [RFE] Transitive AD trusts support
Closed: Fixed None Opened 11 years ago by abbra.

Once we have implemented support for multiple DNS domains per our realm and discovering trusted domains behind AD domain we trust, we need to update logic in KDC driver to consider transitive trusts.

Before that could be implemented we need:

  • Handle DNS suffixes for our domain and export them to trusted domains
  • Fetch and maintain trusted realms out of AD trust
  • be able to filter out both trusted domains and SIDs for them, incoming/outgoing

Tickets #2848, #2593, #3407 would need to be done before this ticket is going to be worked on.


We will need to define proper API for SSSD to create the binding to get the trusted domain list. See related ticket: https://fedorahosted.org/sssd/ticket/1958

3.4 development was shifted by one month, moving tickets to reflect reality better.

Adjusting time plan - 3.4 development was postponed as we focused on 3.3.x testing and stabilization.

Moving unfinished November tickets to January.

Closing the ticket since we implemented all parts.

Metadata Update from @abbra:
- Issue assigned to abbra
- Issue set to the milestone: FreeIPA 3.3.x - 2014/01 (bug fixing)

7 years ago

Login to comment on this ticket.

Metadata