Back to bug 1378440

Who When What Removed Added
Alexander Bokovoy 2016-09-22 12:58:33 UTC CC abokovoy, dpal, pkis
Component ipa krb5
Assignee ipa-maint rharwood
QA Contact ksiddiqu qe-baseos-security
Robbie Harwood 2016-11-14 20:56:47 UTC Priority unspecified high
Status NEW ASSIGNED
Matt Rogers 2017-04-06 16:17:59 UTC CC mrogers
Robbie Harwood 2017-04-06 16:34:01 UTC QA Contact qe-baseos-security pkis
Flags needinfo?(pkis)
Patrik Kis 2017-04-07 09:35:43 UTC Flags needinfo?(pkis)
Robbie Harwood 2017-04-10 19:22:06 UTC Status ASSIGNED MODIFIED
Fixed In Version krb5-1.15.1-7.el7
errata-xmlrpc 2017-04-10 19:23:14 UTC Status MODIFIED ON_QA
Robbie Harwood 2017-05-03 05:52:33 UTC Doc Text Cause: krb5 does not canonicalize principal before handing off to otpd

Consequence: 2fa will mysteriously fail in sssd for users with it enabled

Fix: Use the canonical client principal name for OTP in krb5

Result: IPA forwards the correct principal name
Doc Type If docs needed, set a value Bug Fix
Robbie Harwood 2017-05-17 15:44:12 UTC Flags needinfo?(mrogers)
Matt Rogers 2017-05-17 17:25:21 UTC Flags needinfo?(mrogers)
errata-xmlrpc 2017-05-23 14:44:05 UTC Status ON_QA VERIFIED
errata-xmlrpc 2017-08-01 17:58:41 UTC Status VERIFIED CLOSED
Resolution --- ERRATA
Last Closed 2017-08-01 13:58:41 UTC

Back to bug 1378440