Features/IPAv3TrustImprovements

From FedoraProject

< Features(Difference between revisions)
Jump to: navigation, search
(Created page with " <!-- All fields on this form are required to be accepted by FESCo. We also request that you maintain the same order of sections so that all of the feature pages are uniform....")
 
Line 36: Line 36:
 
== Scope ==
 
== Scope ==
 
<!-- What work do the developers have to accomplish to complete the feature in time for release?  Is it a large change affecting many parts of the distribution or is it a very isolated change? What are those changes?-->
 
<!-- What work do the developers have to accomplish to complete the feature in time for release?  Is it a large change affecting many parts of the distribution or is it a very isolated change? What are those changes?-->
The work is done in the scope of FreeIPA v3.2 upstream development. Additional capabilities are provided as part of SSSD upstream development, designed and tracked [[https://fedorahosted.org/sssd/wiki/DesignDocs/GlobalCatalogLookups | here]]
+
The work is done in the scope of FreeIPA v3.2 upstream development. Additional capabilities are provided as part of SSSD upstream development, designed and tracked [[https://fedorahosted.org/sssd/wiki/DesignDocs/GlobalCatalogLookups here]]
  
 
== How To Test ==
 
== How To Test ==

Revision as of 18:38, 16 January 2013


Contents

FreeIPA v3 Trust Improvements

Summary

Multiple Domain Controllers and multiple additional DNS domains managed by FreeIPA can now be accessible via trusting relationship by Active Directory domain members. Additionally, Global Catalog service is provided for use by AD clients, allowing FreeIPA users to be included into access-control lists of AD resources.

Owner

  • Email: abokovoy@redhat.com

Current status

  • Targeted release: Fedora 19
  • Last updated: 2013-01-16
  • Percentage of completion: 50%


Detailed Description

In Fedora 18 only a single designated Domain Controller in FreeIPA realm is supported for interoperability with Active Directory and only a primary DNS domain associated with the FreeIPA realm is advertised to the trusted party. With the changes coming in FreeIPA v3.2, support for multiple domain controllers per FreeIPA realm and multiple DNS domain suffixes associated with the realm will be available. FreeIPA v3.2 will also provide Global Catalog service implementation which is key feature to allow discretionary access to Active Directory resources for FreeIPA users --- making possible, for example, interactive logon to Windows machines under a FreeIPA identity.

Benefit to Fedora

System administrators, using FreeIPA in Fedora 19, will get access to resources in trusted Active Directory domains. Active Directory domain administrators will be able to authorize access to their machines, services, and applications for FreeIPA-managed users and groups, giving practical bi-directional interoperability.

Scope

The work is done in the scope of FreeIPA v3.2 upstream development. Additional capabilities are provided as part of SSSD upstream development, designed and tracked [here]

How To Test

User Experience

Dependencies

Contingency Plan

Documentation

Release Notes

Comments and Discussion