Currently DAL driver prevents users from using Kerberos-FreeIPA trusts and errors our with "KDC policy rejects request" message.
The check is too restrictive and should be removed.
Details: https://www.redhat.com/archives/freeipa-users/2014-December/msg00045.html
The check should merely be relaxed so that file based configuration can also be used.
Patch sent for review: https://www.redhat.com/archives/freeipa-devel/2015-January/msg00232.html
master:
ipa-4-1:
Metadata Update from @pspacek: - Issue assigned to abbra - Issue set to the milestone: FreeIPA 4.1.3
Login to comment on this ticket.