Bug 958130

Summary: ipa-client-install removes needed options from ldap.conf
Product: Red Hat Enterprise Linux 7 Reporter: Dmitri Pal <dpal>
Component: ipaAssignee: Rob Crittenden <rcritten>
Status: CLOSED CURRENTRELEASE QA Contact: Michael Gregg <mgregg>
Severity: unspecified Docs Contact:
Priority: medium    
Version: 7.0CC: ksiddiqu, mgregg, mkosek
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: ipa-3.2.1-1.el7 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-06-13 13:28:11 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Dmitri Pal 2013-04-30 13:04:31 UTC
This bug is created as a clone of upstream ticket:
https://fedorahosted.org/freeipa/ticket/3582

Ticket was cloned from Red Hat Bugzilla (product ''Fedora''): [https://bugzilla.redhat.com/show_bug.cgi?id=953991 Bug 953991]

{{{
ipa-client-install writes out a custom ldap.conf. We're been using the
SASL_NOCANON option in ldap.conf to unbreak broken upstream defaults. See:

https://bugzilla.redhat.com/show_bug.cgi?id=949864

Ideally we can eventually get a sane default upstream. But either
ipa-client-install should keep settings in ldap.conf, or include 'SASL_NOCANON
on'
}}}

Comment 1 Rob Crittenden 2013-04-30 14:55:40 UTC
Fixed upstream.

master: 5d6a9d3befb5434dd7b2d1bbafd76050f22743a2

Comment 4 Kaleem 2014-01-16 09:12:03 UTC
Verified.

IPA client version:
===================

-------------------[RPMs & OS: [RedHat - x86_64]------------------
|       ipa-client-3.3.3-12.el7.x86_64
|       sssd-ipa-1.11.2-19.el7.x86_64
-------------------------------------------------------------------

Snip from automation log:
=========================

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: [   LOG    ] :: ipaclientinstall_bugcheck_958130 ipa-client-install removes needed options from ldap.conf bz958130
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

:: [   PASS   ] :: Running 'cat /etc/openldap/ldap.conf' (Expected 0, got 0)
:: [   PASS   ] :: Installing ipa-client (Expected 0, got 0)
:: [   PASS   ] :: Running 'cat /etc/openldap/ldap.conf' (Expected 0, got 0)
:: [   PASS   ] :: File '/etc/openldap/ldap.conf' should contain 'SASL_NOCANON on' 
:: [   PASS   ] :: File '/etc/openldap/ldap.conf' should contain 'TLS_CACERT /etc/ipa/ca.crt' 
:: [   PASS   ] :: uninstall ipa client success 
:: [   PASS   ] :: Running 'cat /etc/openldap/ldap.conf' (Expected 0, got 0)
:: [   PASS   ] :: File '/etc/openldap/ldap.conf' should contain 'TLS_CACERTDIR /etc/openldap/cacerts' 
:: [   PASS   ] :: File '/etc/openldap/ldap.conf' should not contain 'TLS_CACERT /etc/ipa/ca.crt' 
:: [   PASS   ] :: File '/etc/openldap/ldap.conf' should contain 'SASL_NOCANON on' 
:: [   LOG    ] :: Duration: 25s
:: [   LOG    ] :: Assertions: 10 good, 0 bad
:: [   PASS   ] :: RESULT: ipaclientinstall_bugcheck_958130 ipa-client-install removes needed options from ldap.conf bz958130

Comment 5 Ludek Smid 2014-06-13 13:28:11 UTC
This request was resolved in Red Hat Enterprise Linux 7.0.

Contact your manager or support representative in case you have further questions about the request.