Bug 1112691
| Summary: | ipa-server-install break sshd | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Martin Kosek <mkosek> |
| Component: | ipa | Assignee: | Martin Kosek <mkosek> |
| Status: | CLOSED ERRATA | QA Contact: | Namita Soman <nsoman> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | medium | ||
| Version: | 7.0 | CC: | jgalipea, jmontleo, ksiddiqu, mkosek, rcritten |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | ipa-4.0.3-1.el7 | Doc Type: | Bug Fix |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2015-03-05 10:12:43 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 1201454 | ||
|
Description
Martin Kosek
2014-06-24 13:40:33 UTC
Fixed upstream master: https://fedorahosted.org/freeipa/changeset/3e0245f28fe3f294f21b8d0cc298b1901119921d Tested with ipa-client-install after I removed the trailing new line in /etc/ssh/sshd_config with: # perl -i -pe 'chomp if eof' /etc/ssh/sshd_config With this fix, the sshd_config is no longer broken. How to QE can verify this? Post IPA server install
UseDNS is commented out in the /etc/ssh/sshd_config
Configuration around line 156 ...
KerberosAuthentication no
PubkeyAuthentication yes
UsePAM yes
AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys
GSSAPIAuthentication yes
AuthorizedKeysCommandUser nobody
sshd service restarts without issue
service is running
# systemctl status sshd.service
sshd.service - OpenSSH server daemon
Loaded: loaded (/usr/lib/systemd/system/sshd.service; enabled)
Active: active (running) since Tue 2015-01-27 09:27:54 EST; 5s ago
Main PID: 24314 (sshd)
CGroup: /system.slice/sshd.service
└─24314 /usr/sbin/sshd -D
Jan 27 09:27:54 ibm-x3250m4-05.testrelm.test systemd[1]: Starting OpenSSH server daemon...
Jan 27 09:27:54 ibm-x3250m4-05.testrelm.test systemd[1]: Started OpenSSH server daemon.
Jan 27 09:27:54 ibm-x3250m4-05.testrelm.test sshd[24314]: Server listening on 0.0.0.0 port 22.
Jan 27 09:27:54 ibm-x3250m4-05.testrelm.test sshd[24314]: Server listening on :: port 22.
Service stops are starts without issue
# systemctl stop sshd.service
# systemctl status sshd.service
sshd.service - OpenSSH server daemon
Loaded: loaded (/usr/lib/systemd/system/sshd.service; enabled)
Active: inactive (dead) since Tue 2015-01-27 09:29:35 EST; 5s ago
Process: 24323 ExecStart=/usr/sbin/sshd -D $OPTIONS (code=exited, status=0/SUCCESS)
Main PID: 24323 (code=exited, status=0/SUCCESS)
Jan 27 09:29:18 ibm-x3250m4-05.testrelm.test systemd[1]: Starting OpenSSH server daemon...
Jan 27 09:29:18 ibm-x3250m4-05.testrelm.test systemd[1]: Started OpenSSH server daemon.
Jan 27 09:29:18 ibm-x3250m4-05.testrelm.test sshd[24323]: Server listening on 0.0.0.0 port 22.
Jan 27 09:29:18 ibm-x3250m4-05.testrelm.test sshd[24323]: Server listening on :: port 22.
Jan 27 09:29:35 ibm-x3250m4-05.testrelm.test systemd[1]: Stopping OpenSSH server daemon...
Jan 27 09:29:35 ibm-x3250m4-05.testrelm.test sshd[24323]: Received signal 15; terminating.
Jan 27 09:29:35 ibm-x3250m4-05.testrelm.test systemd[1]: Stopped OpenSSH server daemon.
# systemctl start sshd.service
# systemctl status sshd.service
sshd.service - OpenSSH server daemon
Loaded: loaded (/usr/lib/systemd/system/sshd.service; enabled)
Active: active (running) since Tue 2015-01-27 09:29:48 EST; 6s ago
Main PID: 24330 (sshd)
CGroup: /system.slice/sshd.service
└─24330 /usr/sbin/sshd -D
Jan 27 09:29:48 ibm-x3250m4-05.testrelm.test systemd[1]: Starting OpenSSH server daemon...
Jan 27 09:29:48 ibm-x3250m4-05.testrelm.test systemd[1]: Started OpenSSH server daemon.
Jan 27 09:29:48 ibm-x3250m4-05.testrelm.test sshd[24330]: Server listening on 0.0.0.0 port 22.
Jan 27 09:29:48 ibm-x3250m4-05.testrelm.test sshd[24330]: Server listening on :: port 22.
# cat /etc/redhat-release
Red Hat Enterprise Linux Server release 7.1 Beta (Maipo)
# rpm -q ipa-server
ipa-server-4.1.0-16.el7.x86_64
Is this enough to verify this bug?
If you updated sshd_config before IPA installation to miss the final line break (as described in Comment 1), then yes. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHSA-2015-0442.html |