Bug 1017292 - krb5-auth-dialog --auto should not exit if the environment contains KRB5CCNAME
krb5-auth-dialog --auto should not exit if the environment contains KRB5CCNAME
Product: Fedora
Classification: Fedora
Component: krb5-auth-dialog (Show other bugs)
Unspecified Unspecified
unspecified Severity unspecified
: ---
: ---
Assigned To: Itamar Reis Peixoto
Fedora Extras Quality Assurance
Depends On:
Blocks: 1017180 1146827
  Show dependency treegraph
Reported: 2013-10-09 11:09 EDT by Stephen Gallagher
Modified: 2014-09-26 03:45 EDT (History)
3 users (show)

See Also:
Fixed In Version: krb5-auth-dialog-3.2.1-7.fc20
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 1146827 (view as bug list)
Last Closed: 2013-11-10 02:28:43 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
Patch to consider KRB5CCNAMe too (923 bytes, patch)
2013-10-09 11:17 EDT, Simo Sorce
no flags Details | Diff

  None (edit)
Description Stephen Gallagher 2013-10-09 11:09:44 EDT
Description of problem:
When installed on Fedora, krb5-auth-dialog will run with the --auto command on every graphical desktop session (tested with GNOME 3, but should be true of at least MATE and Cinnamon as well). The --auto command causes krb5-auth-dialog to exit if there is no credential cache available.

However, there are circumstances (such as when using KEYRING:persistent caches) where the KRB5CCNAME variable may be set, but the cache contents are not yet stored (such as SSSD with offline authentication). krb5-auth-dialog should check whether the KRB5CCNAME variable has been set in the environment and not exit if it is.

Version-Release number of selected component (if applicable):

How reproducible:
Every time

Steps to Reproduce:
1. Configure SSSD with KEYRING:persistent:%{uid} caches
2. Log in to a graphical session while unable to reach the KDC

Actual results:
krb5-auth-dialog is not running when the desktop comes up.

Expected results:
krb5-auth-dialog should be running and inform the user that their credential cache is expired.

Additional info:
Comment 1 Simo Sorce 2013-10-09 11:17:36 EDT
Created attachment 809995 [details]
Patch to consider KRB5CCNAMe too

I tested a build with this patch and does what we need.
Please consider using it and sneding it upstream too.
Comment 2 Jakub Hrozek 2013-10-17 06:01:11 EDT
Hi, any news on reviewing the patch? I'd like to get Simo's patch accepted to avoid having to do any workarounds in the SSSD..
Comment 3 Fedora Update System 2013-11-07 08:00:09 EST
krb5-auth-dialog-3.2.1-7.fc20 has been submitted as an update for Fedora 20.
Comment 4 Fedora Update System 2013-11-07 14:05:41 EST
Package krb5-auth-dialog-3.2.1-7.fc20:
* should fix your issue,
* was pushed to the Fedora 20 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing krb5-auth-dialog-3.2.1-7.fc20'
as soon as you are able to.
Please go to the following url:
then log in and leave karma (feedback).
Comment 5 Fedora Update System 2013-11-10 02:28:43 EST
krb5-auth-dialog-3.2.1-7.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 6 Fedora Update System 2014-04-15 03:17:06 EDT
krb5-auth-dialog-3.2.1-7.fc19 has been submitted as an update for Fedora 19.
Comment 7 Fedora Update System 2014-04-24 03:38:13 EDT
krb5-auth-dialog-3.2.1-7.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.