Bug 1643814
Summary: | realmd.conf user-principal RFE and clarification | |||
---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8 | Reporter: | Erinn Looney-Triggs <erinn.looneytriggs> | |
Component: | realmd | Assignee: | Sumit Bose <sbose> | |
Status: | CLOSED CURRENTRELEASE | QA Contact: | sssd-qe <sssd-qe> | |
Severity: | medium | Docs Contact: | ||
Priority: | unspecified | |||
Version: | 8.2 | CC: | afarley, dpal, pcech, sgoveas, thalman | |
Target Milestone: | rc | Keywords: | FutureFeature | |
Target Release: | --- | |||
Hardware: | All | |||
OS: | Linux | |||
Whiteboard: | ||||
Fixed In Version: | Doc Type: | If docs needed, set a value | ||
Doc Text: | Story Points: | --- | ||
Clone Of: | ||||
: | 1747452 (view as bug list) | Environment: | ||
Last Closed: | 2021-01-28 10:11:47 UTC | Type: | Bug | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Embargoed: | ||||
Bug Depends On: | ||||
Bug Blocks: | 1747452 |
Description
Erinn Looney-Triggs
2018-10-29 04:22:05 UTC
And finally with 'user-principal = yes' in realmd.conf using adcli (this is on Fedora 29 for testing sake) UPN is set to host/example. If user-principal is ommited from the command line realm join or from realmd.conf NO UPN is created, this again seems to contradict the man pages. I suppose at a minimum consistency would be very very useful here. Hi, thank you for the ticket. I agree the documentation of the user-principal options need some improvement. Especially there is no mention of the "default" user principal 'NETBIOSNAME$@AD.REALM' which is used by AD automatically even if there is no userPrincipalName attribute set and which is still the 'canonical' principal even if userPrincipalName is set (can be checked with kinit -C ...). About the RFE to be able to specify the user-principal in realmd.conf as well. I agree that is good if command line argument and realmd.conf options are consistent. But I wonder how useful client specific settings are in a config file which typically contains other values which should be shared between multiple clients. Yes, there already is 'computer-name' but I wonder what your use case would be for being able to set the user principal explicitly in realmd.conf. Honestly my reasons would be for consistency sake. I use 'computer-name' as well and I guess my expectations for realmd.conf is to do the same as the command line does, it is fine though if it doesn't. This is mainly due to the questions asked here: https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.org/thread/RPPIQ43IIUODZESOHNOOAFSNBN7PWV62/ adcli creates one type of UPN, samba creates another, I am just trying to build a consistent environment where I can be assured that the UPN is set to something consistent across all of my systems. So I suppose I could pass that in on the command line, I was just expecting realmd.conf to basically do the same as the command line. -Erinn Upstream: - d6d1ce2f8b1c81903115b018973c61fc71235b7b The needinfo request[s] on this closed bug have been removed as they have been unresolved for 500 days |