Bug 591681

Summary: RFE: Gray out KDC and admin fields when kerberos parameters are discovered via DNS
Product: [Fedora] Fedora Reporter: Stjepan Gros <stjepan.gros>
Component: authconfigAssignee: Tomas Mraz <tmraz>
Status: CLOSED RAWHIDE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: low    
Version: 13CC: jhrozek, sgallagh, tmraz
Target Milestone: ---Keywords: FutureFeature
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: authconfig-6.1.5-1.fc14 Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of:
: 591716 (view as bug list) Environment:
Last Closed: 2010-08-10 14:18:35 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 591716    

Description Stjepan Gros 2010-05-12 20:09:40 UTC
Description of problem:

After selecting FreeIPA as authentication server in authconfig and marking checkbox 'Use DNS to locate KDC for realms' it would be good that the fields KDCs and 'Admin servers' are grayed out?

Version-Release number of selected component (if applicable):
authconfig-6.1.4-2.fc13.x86_64

How reproducible:
Always

Steps to Reproduce:
1. Just configure FreeIPA authentication with DNS used to locate KDCs.

Additional info:
In /etc/krb5.conf DNS resolution is selected and in the sam time values of KDC and admin server are filled with exact values. The question is which values have higher priority?

Comment 1 Tomas Mraz 2010-05-12 20:30:39 UTC
According to the krb5.conf manpage the DNS is used only when the realm and KDC is not filled in. I am not sure whether sssd behaves the same.

Comment 2 Stephen Gallagher 2010-05-12 20:52:27 UTC
Jakub, can you clarify? I think our default behavior is the same, but you're the authority.

Comment 3 Jakub Hrozek 2010-05-13 09:52:37 UTC
Yes, even though we don't have any equivalent of dns_lookup_kdc (which is the krb5.conf option set by the 'Use DNS to locate KDC for realms' checkbox), we always use service discovery when no KDCs are set.

We don't have any equivalent of 'dns_lookup_realm' in SSSD at all - which is the second check box "Use DNS to resolve hosts to realms".

Comment 4 Stjepan Gros 2010-05-13 10:05:42 UTC
Kerberos realm is also retrieved from DNS, so it also should be either grayed out or maybe automatically filled in.