Bug 1116010

Summary: Enable ad_compat sasl option
Product: Red Hat Enterprise Linux 6 Reporter: Dmitri Pal <dpal>
Component: sssdAssignee: Jakub Hrozek <jhrozek>
Status: CLOSED ERRATA QA Contact: Kaushik Banerjee <kbanerje>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 6.6CC: dlavu, grajaiya, jgalipea, lslebodn, mkosek, pbrezina, preichl
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: sssd-1.11.6-1.el6 Doc Type: Bug Fix
Doc Text:
No Documentation Needed
Story Points: ---
Clone Of: 1007474 Environment:
Last Closed: 2014-10-14 04:48:56 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 994242, 1007474    
Bug Blocks:    

Description Dmitri Pal 2014-07-03 13:46:45 UTC
+++ This bug was initially created as a clone of Bug #1007474 +++

This bug is created as a clone of upstream ticket:
https://fedorahosted.org/sssd/ticket/2040

The sasl library has introduced an option to keep AD happy when SASL/GSSAPI is being used: http://git.cyrusimap.org/cyrus-sasl/commit/plugins/gssapi.c?id=cccc5a5a87a74cd434fbdf5e87c4158e21ebcf19

Take advantage of this option in the sssd_ad code.

--- Additional comment from Martin Kosek on 2014-06-17 08:14:11 EDT ---

Fixed upstream:

fb945a2cacc5506a2acb50349670f22078f1d4f5

Comment 2 Dan Lavu 2014-07-25 15:19:44 UTC
Verified enhancement on sssd-1.11.6-4.el6.x86_64 using Windows 2012 AD. 
Setting up AD with LDAP server signing using GPOs on the default domain policy. Configured AD following this KB article: https://support.microsoft.com/kb/935834

Moving to verified.

Comment 4 errata-xmlrpc 2014-10-14 04:48:56 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2014-1375.html