Right now we do not have a good way of defining a policy about the user account. What we have is a set of the organically grown features. We need to step back and allow users to define acceptable authentication policies that organization might have.
Examples of the use cases: - As an admin I want to disable users whose password expired to log with SSH keys - As an admin I want to deliberately disable password authentication and allow only SSH authentication - As an admin I want to disallow SSH key authentication if user has a smart card or OTP provisioned to him. - As and admin I want to allow user to choose SC, SSH, or PWD authentication at their own discretion. - As an admin I want to be able to very the policy per host.
Looking at the use cases the policy seems to be something like: - For these users or groups of users or all - For whom a specific condition or state of the account is met (has XYZ credentials provisioned, authentication methods enabled, account enabled/disabled, password expired, a specific attribute set, etc.) - Accessing a specific host or group of hosts or all - Only specific authentication methods or workflows (like 1F -> 2F step up) should be allowed
Metadata Update from @dpal: - Issue assigned to someone - Issue set to the milestone: Ticket Backlog
Thank you taking time to submit this request for FreeIPA. Unfortunately this bug was not given priority and the team lacks the capacity to work on it at this time.
Given that we are unable to fulfil this request I am closing the issue as wontfix. To request re-consideration of this decision please reopen this issue and provide additional technical details about its importance to you.
Metadata Update from @rcritten: - Issue close_status updated to: wontfix - Issue status updated to: Closed (was: Open)