Bug 1456835

Summary: KRB5CCNAME should show relevant fields for cache type KCM
Product: Red Hat Enterprise Linux 7 Reporter: Amith <apeetham>
Component: sssdAssignee: SSSD Maintainers <sssd-maint>
Status: CLOSED NOTABUG QA Contact: sssd-qe <sssd-qe>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 7.4CC: grajaiya, jhrozek, lslebodn, mkosek, mzidek, pbrezina, tscherf
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-05-30 13:22:19 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Amith 2017-05-30 13:11:05 UTC
Description of problem:
The format for KRB5CCNAME is KCM:$NAME:$CACHE_ID, when KCM cache is used. However this variable shows just "KCM:".

Version-Release number of selected component (if applicable):
sssd-1.15.2-37.el7.x86_64

How reproducible:
Always

Steps to Reproduce:
1. Run user login and fetch the krb ticket. 
    # ssh -l testuser localhost
    [testuser@vm-idm-020 ~]$ klist
    Ticket cache: KCM:21201:48692
    Default principal: testuser

2. Verify the contents of variable KRB5CCNAME
   [testuser@vm-idm-020 ~]$ echo $KRB5CCNAME
   KCM:

Result Seen:
KCM:

Expected results:
The KRB5CCNAME variable should be in the form of KCM:$NAME:$CACHE_ID.
It should show relevant field values.

Comment 2 Jakub Hrozek 2017-05-30 13:22:19 UTC
No, this is by design. The collection is identified just by KCM.

I admit this got me confused as well, but see the reply from the upstream MIT Kerberos maintainer:
https://github.com/krb5/krb5/pull/557#issuecomment-254834623