Bug 1115854 - Investigate using the krb5 responder for driving the PAM conversation with OTPs
Summary: Investigate using the krb5 responder for driving the PAM conversation with OTPs
Status: CLOSED DUPLICATE of bug 919228
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: sssd
Version: 7.0
Hardware: Unspecified
OS: Unspecified
Target Milestone: rc
: ---
Assignee: Jakub Hrozek
QA Contact: Kaushik Banerjee
Depends On:
TreeView+ depends on / blocked
Reported: 2014-07-03 09:14 UTC by Jakub Hrozek
Modified: 2020-05-02 17:42 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2014-07-23 15:41:10 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Github SSSD sssd issues 3377 0 None None None 2020-05-02 17:42:40 UTC

Description Jakub Hrozek 2014-07-03 09:14:12 UTC
This bug is created as a clone of upstream ticket:

We need logic in SSSD that would allow the GDM prompter to prompt the user for long-term password and the OTP in different prompts. 

Nathaniel suggested to use the krb5 responder callback. Citing from his proposal:

That is, the user name is selected in GDM and SSSD begins the krb5 connection. The responder callback is called. Within this callback, SSSD can see exactly what mechanisms can be used to authenticate the user. No connection to LDAP is needed. This should drive the responses (all within the callback). There is no guarantee that SSSD’s analysis of LDAP will drive the choices actually available in the responder callback.

However, I don’t know how this could be done while preserving the communication protocol between the parent and child processes.

Comment 1 Kaushik Banerjee 2014-07-23 15:41:10 UTC

*** This bug has been marked as a duplicate of bug 919228 ***

Note You need to log in before you can comment on or make changes to this bug.