Bug 1018189

Summary: authconfig / sssd.conf: "dns_discovery_domain" issue
Product: Red Hat Enterprise Linux 6 Reporter: guillard <orglube>
Component: authconfigAssignee: Tomas Mraz <tmraz>
Status: CLOSED WONTFIX QA Contact: BaseOS QE Security Team <qe-baseos-security>
Severity: high Docs Contact:
Priority: unspecified    
Version: 6.6CC: ebenes, mgrigull, sgallagh
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-08-11 11:06:15 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description guillard 2013-10-11 12:02:37 UTC
Description of problem:
if sssd uses dns discovery to look for ldap servers, then
the DNS zone to query for ldap server is specified with
the parameter "dns_discovery_domain" in sssd.conf, and the
parameter "ldap_uri" should not be declared.

If "dns_discovery_domain" is specified in sssd.conf, then
the configuration script 'authconfig' should not insert an
"ldap_uri"in sssd.conf, which it does.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:

1. edit sssd.conf and declare a "dns_discovery_domain" domain

2. launch "authconfig" with apropriate flags: --ldapserver="ldap.example.com" --enableshadow  --enablesssd --enablesssdauth --enableldap --enableldapauth --updateall

3. "ldap_uri"

Actual results:

the following line has been added to sssd.conf :

ldap_uri = ldap.example.com

Expected results:

this line should not be inserted to sssd.conf

Additional info:

After tshark investigations, it sounds like when both "ldap_uri" and "dns_discovery_domain" are declared in sssd.conf, then sssd uses ldap servers declared in "ldap_uri" server rather than querying the dns to look for the relevant ldap server to work with.

Comment 1 Tomas Mraz 2013-10-11 12:10:16 UTC
Authconfig cannot recognize all the possible configuration options that sssd supports. Just do not use it at all, or use it just for pam configuration - that is use --enablesssd --enablesssdauth but not --enableldap and the ldapserver and related options.

Comment 2 guillard 2013-10-13 18:17:33 UTC
Hi Tomas,

I understand your point. I'm sure that I will be able to find a workaround.
However I beleived that authconfig should support some sort of "ldapdnsdiscovery" option.


Comment 4 Tomas Mraz 2016-08-11 11:06:15 UTC
I am sorry but we are not going to implement this feature at this time.