Bug 1856315

Summary: Fix net-ads-join with LDAP over TLS
Product: Red Hat Enterprise Linux 8 Reporter: Isaac Boukris <iboukris>
Component: sambaAssignee: Isaac Boukris <iboukris>
Status: CLOSED ERRATA QA Contact: sssd-qe <sssd-qe>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 8.3CC: asn, dkarpele, gdeschner, iboukris, jarrpa
Target Milestone: rcFlags: pm-rhel: mirror+
Target Release: 8.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: samba-4.12.3-10.el8.3 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-11-04 02:00:01 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1804121    

Description Isaac Boukris 2020-07-13 11:45:50 UTC
Currently net-ads-join does not work with "ldap ssl ads" due to hardcoded sasl wrapping.
We need upstream fixes of #14439 and #13124.

Comment 3 Isaac Boukris 2020-07-15 11:31:27 UTC
Note, with this fix it is also no longer needed to specify "client ldap sasl wrapping = plain" for net-ads commands, as it is now done implicitly when over TLS.

Comment 7 errata-xmlrpc 2020-11-04 02:00:01 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (samba bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2020:4543