> Having said that, I'm not even sure if one can request a specific preauth 
> method today
> in SSSD.

And by that I mean as a hint before the actual AS_REQ. IIUC this isn't 
straightforward to do currently because: 
- The PAM conversation happens after the AS_REP and depends on the supported 
auth methods
- There is no password fallback with the idp auth 

The other way would be to contact both KDC and somehow keep track of both until 
you get the user input, but it gets tricky
--
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to