Bug 1026845 - Server does not detect different server and IPA domain
Server does not detect different server and IPA domain
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: ipa (Show other bugs)
Unspecified Unspecified
medium Severity unspecified
: rc
: ---
Assigned To: Martin Kosek
Namita Soman
Depends On:
  Show dependency treegraph
Reported: 2013-11-05 09:16 EST by Dmitri Pal
Modified: 2014-06-17 20:12 EDT (History)
3 users (show)

See Also:
Fixed In Version: ipa-3.3.3-3.el7
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2014-06-13 07:36:34 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Dmitri Pal 2013-11-05 09:16:35 EST
This bug is created as a clone of upstream ticket:

Server domain is being checked if it is in a main IPA domain. When not, additional realm_domain mapping is added to `/etc/krb5.conf`.

However, given that the domain is checked just with string comparison of the domain, when the server has fqdn like `ipa-idm.example.com` and main domain and realm is `idm.example.com`, the installer does not detect this mismatch, does not configure realm_domain mapping and httpd does not start due to obscure error:

gss_acquire_cred() failed: Unspecified GSS failure.  Minor code may provide more
information (, ), referer: https://ipa-idm.example.com/ipa/xml
Comment 1 Namita Soman 2013-11-05 12:45:44 EST
Please provide steps to verify
Comment 2 Martin Kosek 2013-11-06 04:27:56 EST
Reproduction scenario:

1) Install IPA so that server FQDN lies in different domain than the main domain (--domain) but shares the same suffix. E.g.:

# hostname ipa-idm.example.com
# ipa-server-install --domain idm.example.com

2) When installation is complete, try kinit and one command:
# kinit admin
# ipa user-show admin

ipa command will fail with the old version as realm-domain mapping is missing in /etc/krb5.conf.
Comment 5 Scott Poore 2014-01-29 13:37:47 EST

Version ::


Test Results ::

[root@rhel7-4 ~]# sed -i "/$(hostname -i)/d" /etc/hosts

[root@rhel7-4 ~]# sed -i "/$(hostname)/d" /etc/hosts

[root@rhel7-4 ~]# cat /etc/hosts   localhost localhost.localdomain localhost4 localhost4.localdomain4
::1         localhost localhost.localdomain localhost6 localhost6.localdomain6

[root@rhel7-4 ~]# echo "$(hostname -i) ipa-idm.example.com" >> /etc/hosts

[root@rhel7-4 ~]# echo ipa-idm.example.com > /etc/hostname

[root@rhel7-4 ~]# hostname ipa-idm.example.com

[root@rhel7-4 ~]# hostname

[root@rhel7-4 ~]# ipa-server-install --setup-dns --forwarder= -r IDM.EXAMPLE.COM -n idm.example.com -p Secret123 -P Secret123 -a Secret123 -U

[root@rhel7-4 ~]# kinit admin
Password for admin@IDM.EXAMPLE.COM: 

[root@rhel7-4 ~]# ipa user-show admin
  User login: admin
  Last name: Administrator
  Home directory: /home/admin
  Login shell: /bin/bash
  UID: 997600000
  GID: 997600000
  Account disabled: False
  Password: True
  Member of groups: admins, trust admins
  Kerberos keys available: True
[root@rhel7-4 ~]# cat /etc/krb5.conf
includedir /var/lib/sss/pubconf/krb5.include.d/

 default = FILE:/var/log/krb5libs.log
 kdc = FILE:/var/log/krb5kdc.log
 admin_server = FILE:/var/log/kadmind.log

 default_realm = IDM.EXAMPLE.COM
 dns_lookup_realm = false
 dns_lookup_kdc = true
 rdns = false
 ticket_lifetime = 24h
 forwardable = yes
 default_ccache_name = KEYRING:persistent:%{uid}

  kdc = ipa-idm.example.com:88
  master_kdc = ipa-idm.example.com:88
  admin_server = ipa-idm.example.com:749
  default_domain = idm.example.com
  pkinit_anchors = FILE:/etc/ipa/ca.crt

 .idm.example.com = IDM.EXAMPLE.COM
 idm.example.com = IDM.EXAMPLE.COM
 .example.com = IDM.EXAMPLE.COM
 example.com = IDM.EXAMPLE.COM

    db_library = ipadb.so

[root@rhel7-4 ~]#
Comment 6 Ludek Smid 2014-06-13 07:36:34 EDT
This request was resolved in Red Hat Enterprise Linux 7.0.

Contact your manager or support representative in case you have further questions about the request.

Note You need to log in before you can comment on or make changes to this bug.