Bug 902716
Summary: | Rule mismatch isn't noticed before smart refresh on ppc64 and s390x | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 6 | Reporter: | Nikolai Kondrashov <nikolai.kondrashov> | ||||||||
Component: | sssd | Assignee: | Jakub Hrozek <jhrozek> | ||||||||
Status: | CLOSED ERRATA | QA Contact: | Kaushik Banerjee <kbanerje> | ||||||||
Severity: | unspecified | Docs Contact: | |||||||||
Priority: | unspecified | ||||||||||
Version: | 6.4 | CC: | dpal, grajaiya, jgalipea, okos, pbrezina, tlavigne | ||||||||
Target Milestone: | rc | ||||||||||
Target Release: | --- | ||||||||||
Hardware: | Unspecified | ||||||||||
OS: | Unspecified | ||||||||||
Whiteboard: | |||||||||||
Fixed In Version: | sssd-1.9.2-79.el6 | Doc Type: | Bug Fix | ||||||||
Doc Text: |
No documentation needed.
|
Story Points: | --- | ||||||||
Clone Of: | Environment: | ||||||||||
Last Closed: | 2013-02-21 09:43:49 UTC | Type: | Bug | ||||||||
Regression: | --- | Mount Type: | --- | ||||||||
Documentation: | --- | CRM: | |||||||||
Verified Versions: | Category: | --- | |||||||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||||
Cloudforms Team: | --- | Target Upstream Version: | |||||||||
Embargoed: | |||||||||||
Bug Depends On: | |||||||||||
Bug Blocks: | 905536 | ||||||||||
Attachments: |
|
Description
Nikolai Kondrashov
2013-01-22 10:28:39 UTC
Created attachment 685018 [details]
mismatch_refresh_test.ldif
Created attachment 685019 [details]
sssd.conf
Created attachment 685034 [details]
mismatch_refresh_test.ldif
I'd say this bug could lead to a security issue, where an administrator would expect access right revocation to become effective immediately on ppc64 or s390x, similarly to what happens on i386 or x86_64, and not only after smart refresh interval, which could be set noticeably long. Upstream ticket: https://fedorahosted.org/sssd/ticket/1779 Hi, can you please attach logs? Also, would you be so kind as to prepare me test environment on these architectures? Thanks. (In reply to comment #7) > Hi, > can you please attach logs? Also, would you be so kind as to prepare me test > environment on these architectures? Thanks. Details on reproduction environment were passed on IRC. Verified as fixed with the following packages: sssd-client-1.9.2-82.el6.s390x libsss_idmap-1.9.2-82.el6.s390x sssd-1.9.2-82.el6.s390x libsss_sudo-1.9.2-82.el6.s390x Relevant sudo suite output: :: [ PASS ] :: refresh_mod_rule_user_to_mismatch Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHSA-2013-0508.html |