Bug 688158

Summary: [gdm] Login using LDAP authentication isn't handled well in gdm-binary
Product: Red Hat Enterprise Linux 6 Reporter: Jakub Libosvar <jlibosva>
Component: gdmAssignee: Ray Strode [halfline] <rstrode>
Status: CLOSED ERRATA QA Contact: Desktop QE <desktop-qa-list>
Severity: urgent Docs Contact:
Priority: unspecified    
Version: 6.1CC: cpelland, iheim, rstrode, tpelka
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: gdm-2.30.4-24.el6 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-12-06 17:57:58 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 661713    
Attachments:
Description Flags
Messages and secure logs none

Description Jakub Libosvar 2011-03-16 13:52:29 UTC
Created attachment 485737 [details]
Messages and secure logs

Description of problem:
When using UPN or domain\uname on logging to machine, parameter passed to id doesn't escape backslash which leads to failure obtaining uid (passed is 'id -u domain\name' instead of 'id -u domain\\name'

Version-Release number of selected component (if applicable):
gdm-2.30.4-21

How reproducible:
Always

Steps to Reproduce:
1. Have LDAP authentication
2. Try to login with user from LDAP
  
Actual results:
Password is authenticated successfully but when gdm-binary is obtaining user's id, it fails and user gets back to login screen

Expected results:
User is logged in successfully

Additional info:
messages, secure log attached

Mar 16 14:34:47 r6-x86-d gdm-binary[1740]: WARNING: Command 'id -u RHEV\vdcadmin' exited unsuccessfully with code: 1

[root@r6-x86-d log]# id -u rhev\vdcadmin
id: rhevvdcadmin: No such user
[root@r6-x86-d log]# id -u rhev\\vdcadmin
16777216

Comment 2 RHEL Program Management 2011-03-16 14:08:12 UTC
This request was evaluated by Red Hat Product Management for
inclusion in the current release of Red Hat Enterprise Linux.
Because the affected component is not scheduled to be updated
in the current release, Red Hat is unfortunately unable to
address this request at this time. Red Hat invites you to
ask your support representative to propose this request, if
appropriate and relevant, in the next release of Red Hat
Enterprise Linux. If you would like it considered as an
exception in the current release, please ask your support
representative.

Comment 3 Ray Strode [halfline] 2011-05-04 15:28:25 UTC
ah, this is probably a side effect of the workaround mentioned by bug 621700
the patch has:

command_line = g_strdup_printf ("id -u %s", username);

and it should probably have

command_line = g_strdup_printf ("id -u '%s'", username);


(and likewise for group)

Comment 4 RHEL Program Management 2011-05-23 15:19:30 UTC
This request was evaluated by Red Hat Product Management for inclusion
in a Red Hat Enterprise Linux maintenance release. Product Management has 
requested further review of this request by Red Hat Engineering, for potential
inclusion in a Red Hat Enterprise Linux Update release for currently deployed 
products. This request is not yet committed for inclusion in an Update release.

Comment 6 Ray Strode [halfline] 2011-07-27 20:33:39 UTC
a fix for this is building now

Comment 9 errata-xmlrpc 2011-12-06 17:57:58 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2011-1721.html