Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1080209 - IPA server does not allow sudo host network filters
IPA server does not allow sudo host network filters
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: ipa (Show other bugs)
7.0
Unspecified Unspecified
medium Severity unspecified
: rc
: ---
Assigned To: Martin Kosek
Namita Soman
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2014-03-24 18:25 EDT by Patrick Hemmer
Modified: 2015-03-05 05:10 EST (History)
4 users (show)

See Also:
Fixed In Version: ipa-4.0.3-1.el7
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-03-05 05:10:41 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:0442 normal SHIPPED_LIVE Moderate: ipa security, bug fix, and enhancement update 2015-03-05 09:50:39 EST

  None (edit)
Description Patrick Hemmer 2014-03-24 18:25:40 EDT
Description of problem:
Attempting to set a subnet in an external host filter for a sudo rule fails with "IPA Error 3009".


Version-Release number of selected component (if applicable):
ipa-server-3.0.0-26.el6_4.2.x86_64


Steps to Reproduce:
1. Create a sudo rule
2. Add "10.0.0.0/8" as an external host.
3. 

Actual results:
IPA Error 3009
invalid 'host': only letters, numbers, _, and - are allowed. DNS label may not start or end with -


Expected results:
success


Additional info:
The sudoers man page defines a host filter as:
Host ::= '!'* host name |
         '!'* ip_addr |
         '!'* network(/netmask)? |
         '!'* +netgroup |
         '!'* Host_Alias

The sudoers.ldap man page even says the 'sudoHost' LDAP attribute supports "IP network".

Thus "10.0.0.0/8" should be accepted as a valid host filter.
Comment 4 Martin Kosek 2014-03-26 05:42:45 EDT
This looks like another gap in our sudo compat tree generation code. See also Bug 1066572. I will open upstream ticket.
Comment 5 Martin Kosek 2014-03-26 05:43:27 EDT
Upstream ticket:
https://fedorahosted.org/freeipa/ticket/4274
Comment 8 Scott Poore 2015-01-26 20:04:51 EST
Verified.

Version ::

ipa-server-4.1.0-16.el7.x86_64

Results ::

[root@rhel7-1 sssd]# ipa help sudorule-add-host
Usage: ipa [global-options] sudorule-add-host SUDORULE-NAME [options]

Add hosts and hostgroups affected by Sudo Rule.
Options:
  -h, --help        show this help message and exit
  --all             Retrieve and print all attributes from the server. Affects
                    command output.
  --raw             Print entries as stored on the server. Only affects output
                    format.
  --hosts=STR       hosts to add
  --hostgroups=STR  host groups to add
  --hostmask=STR    host masks of allowed hosts


[root@rhel7-1 sssd]# ipa sudorule-add-host test --hostmask='10.0.0.0/8' --hosts=''
  Rule name: test
  Enabled: TRUE
  Host Masks: 10.0.0.0/8
-------------------------
Number of members added 1
-------------------------

FYI, needed --hosts='' for avoiding interactive mode asking for host.
Comment 10 errata-xmlrpc 2015-03-05 05:10:41 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHSA-2015-0442.html

Note You need to log in before you can comment on or make changes to this bug.