Bug 819002

Summary: [RFE] Hide password creation and Email fields at user creation time if LDAP auth is enabled in CFSE
Product: [Retired] Subscription Asset Manager Reporter: Eric Sammons <esammons>
Component: katelloAssignee: Jordan OMara <jomara>
Status: CLOSED ERRATA QA Contact: Og Maciel <omaciel>
Severity: urgent Docs Contact:
Priority: unspecified    
Version: 1.0.0CC: athomas, bkearney, jomara, omaciel, tkolhar, tomckay
Target Milestone: betaKeywords: FutureFeature, Triaged
Target Release: 1.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of:
: 820626 858358 (view as bug list) Environment:
Last Closed: 2013-02-21 19:15:56 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 816564, 820626, 858358, 876492    

Description Eric Sammons 2012-05-04 14:56:00 UTC
Description of problem:
When warden is set to ldap the New User option should not be visible as local users are not supported.  When a new user is created via the New User option from a LDAP configured instance that user will be unable to login due to the warden value being set to ldap.

Version-Release number of selected component (if applicable):
katello-headpin-all-0.2.6-1.el6_2.noarch


Steps to Reproduce:
1. Configure SAM (Katello) with auth type ldap.
2. Login with an administrative user
3. Navigate to the Administrator / Users tab
4. Note the New User option is available
5. Create new user
6. logout
7. Attempt to login with new user
  
Actual results:
Unable to login

Expected results:
Either support multiple wardens, r/w access to the ldap to create new users, or disable the new user link when warden is ldap.

Comment 1 Jordan OMara 2012-05-07 19:07:06 UTC
The new user option is still valid under LDAP. Adding a user w/ a valid LDAP username allows you to set additional roles for that user. 

It might be worthwhile to remove the ability to set a password for the user, since that password would never get used in LDAP mode

Comment 2 Jordan OMara 2012-05-08 21:10:26 UTC
Changing to RFE to disallow password setting on new user creation in LDAP auth mode

Comment 4 Jordan OMara 2012-06-19 12:33:08 UTC
merged https://github.com/Katello/katello/pull/213/

Admins are no longer prompted for email/password when creating LDAP users

However, if for some reason they disable LDAP mode after install (I'm not sure if this is supported or not) those users will not be able to login until a password is set by an admin

Comment 5 Og Maciel 2012-10-09 22:06:59 UTC
Verified:

* candlepin-0.7.12-1.el6_3.noarch
* candlepin-tomcat6-0.7.12-1.el6_3.noarch
* katello-candlepin-cert-key-pair-1.0-1.noarch
* katello-certs-tools-1.1.8-1h.el6_3.noarch
* katello-cli-common-1.1.10-1h.el6_3.noarch
* katello-cli-headpin-0.2.2-1.el6_2.noarch
* katello-common-1.1.14-2h.el6_3.noarch
* katello-configure-1.1.11-1h.el6_3.noarch
* katello-glue-candlepin-1.1.14-2h.el6_3.noarch
* katello-headpin-1.1.14-2h.el6_3.noarch
* katello-headpin-all-1.1.14-2h.el6_3.noarch
* katello-selinux-1.1.2-1h.el6_3.noarch

Comment 7 errata-xmlrpc 2013-02-21 19:15:56 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHSA-2013-0544.html