Bug 1791823

Summary: wbinfo -K doesn't work for users of trusted domains/forests
Product: Red Hat Enterprise Linux 7 Reporter: Andreas Schneider <asn>
Component: sambaAssignee: Andreas Schneider <asn>
Status: CLOSED ERRATA QA Contact: Andrej Dzilský <adzilsky>
Severity: high Docs Contact:
Priority: high    
Version: 7.9CC: asn, dkarpele, gdeschner, iboukris, jarrpa, jstephen, tscherf
Target Milestone: rcKeywords: ZStream
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: samba-4.10.4-11.el7 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 1797560 (view as bug list) Environment:
Last Closed: 2020-09-29 20:19:06 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1788833, 1797560    

Description Andreas Schneider 2020-01-16 14:30:18 UTC
Description of problem:

wbinfo -K relies on winbindd (on a domain member) having a complete picture of the trust topology (which is managed by the DCs).

This is just not possible for a domain member!
There might be uPNSuffixes and msDS-SPNSuffixes values, which don't belong to any AD domain at all.

With "winbind scan trusted domains = no" we don't even get an incomplete
picture of the topology.

Instead we should just rely on the [K]DCs of our primary domain (e.g. PRIMARY.A.EXAMPLE.COM) and use enterprise principals e.g. pnfromB.COM.EXAMPLE.COM and follow the WRONG_REALM referrals in order to find the correct DC.

The final principal might be userfromB.PRIVATE.

Comment 11 errata-xmlrpc 2020-09-29 20:19:06 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Moderate: samba security, bug fix, and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2020:3981