Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1146860 - [RFE] Offer OTP generation for host enrollment in the UI
[RFE] Offer OTP generation for host enrollment in the UI
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: ipa (Show other bugs)
7.2
Unspecified Unspecified
unspecified Severity medium
: rc
: ---
Assigned To: IPA Maintainers
Namita Soman
Marc Muehlfeld
: FutureFeature
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2014-09-26 05:19 EDT by David Jaša
Modified: 2016-11-04 01:44 EDT (History)
8 users (show)

See Also:
Fixed In Version: ipa-4.4.0-1.el7
Doc Type: Enhancement
Doc Text:
IdM now supports OTP generation in the Web UI Identity Management (IdM) now supports one-time password (OTP) generation when adding a host in the Web UI. Select the "Generate OTP" check box in the "Add host" dialog. After adding the host, a window displays the generated OTP. You can use this password to join the host to the domain. This procedure simplifies the process and provides a strong OTP. To override the OTP, navigate to the host's details page, click, "Action" and select "Reset One-Time-Password".
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-11-04 01:44:10 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Verified on ipa-server-4.4.0-12.el7.x86_64 (26.57 KB, image/png)
2016-09-19 03:10 EDT, Varun Mylaraiah
no flags Details


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2016:2404 normal SHIPPED_LIVE ipa bug fix and enhancement update 2016-11-03 09:56:18 EDT

  None (edit)
Description David Jaša 2014-09-26 05:19:21 EDT
Description of problem:
Users are quite certain not to come up with random (high-entropy) passwords, let alone with high-entropy one time passwords. IMHO IPA should at least offer to generate OTPs for host enrollment in the UI, or if there are no backward-compatibility concerns, use generation as a default method with custom OTPs as a user-requested fallback

Version-Release number of selected component (if applicable):
ipa-server-3.0.0-37.el6.x86_64 / RHEL 6.5

How reproducible:
always

Steps to Reproduce:
1. add a host in the Web UI
2. set an Enrollment OTP for the host
3.

Actual results:
user is requested to type and retype the password

Expected results:
user should be offered with generated OTP by default

Additional info:
Comment 1 Jan Cholasta 2014-10-02 05:16:53 EDT
It is possible to request a random one-time password when adding a host in the CLI, so I guess it should be possible in the UI as well.
Comment 2 Jan Cholasta 2014-10-02 05:18:41 EDT
Upstream ticket:
https://fedorahosted.org/freeipa/ticket/4602
Comment 3 Martin Kosek 2015-10-07 08:42:23 EDT
This Bugzilla is a feature request and as such is not a good fit for IdM in RHEL-6 where IdM server is only being stabilized and new functionality is not being added.

I am thus moving the Bugzilla to RHEL-7.x series. When/if the RFE is implemented and you are interested in having it backported to IdM in RHEL-6, please clone a Bugzilla to RHEL-6 and provide business justification so that we can re-consider.
Comment 4 Petr Vobornik 2016-06-02 12:40:12 EDT
Fixed upstream
master:
https://fedorahosted.org/freeipa/changeset/3b37e29ac6e918027b06e574c2c793f6c521100c
Comment 5 Petr Vobornik 2016-07-13 10:55:07 EDT
this bz was part of rebase
Comment 7 Varun Mylaraiah 2016-09-19 03:10 EDT
Created attachment 1202323 [details]
Verified on ipa-server-4.4.0-12.el7.x86_64
Comment 11 errata-xmlrpc 2016-11-04 01:44:10 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-2404.html

Note You need to log in before you can comment on or make changes to this bug.