Bug 1163806 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option
Summary: [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using...
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: sssd
Version: 7.1
Hardware: x86_64
OS: Linux
Target Milestone: rc
: ---
Assignee: Pavel Reichl
QA Contact: Dan Lavu
Milan Navratil
Depends On: 1161564
Blocks: 1075802 1181710
TreeView+ depends on / blocked
Reported: 2014-11-13 13:58 UTC by Martin Kosek
Modified: 2020-05-04 10:42 UTC (History)
16 users (show)

Fixed In Version: sssd-1.13.0-0.1.alpha.el7
Doc Type: Release Note
Doc Text:
SSSD supports overriding automatically discovered AD site The Active Directory (AD) DNS site to which the client connects is discovered automatically by default. However, the default automatic search might not discover the most suitable AD site in certain setups. In such situations, you can now define the DNS site manually using the *ad_site* parameter in the *[domain/NAME]* section of the */etc/sssd/sssd.conf* file.
Clone Of: 1161564
Last Closed: 2015-11-19 11:35:06 UTC
Target Upstream Version:
dlavu: needinfo-

Attachments (Terms of Use)

System ID Priority Status Summary Last Updated
Github SSSD sssd issues 3528 None None None 2020-05-04 10:42:48 UTC
Red Hat Product Errata RHSA-2015:2355 normal SHIPPED_LIVE Low: sssd security, bug fix, and enhancement update 2015-11-19 10:27:42 UTC

Comment 1 Jakub Hrozek 2015-04-08 08:19:33 UTC
Fixed upstream:

Comment 8 Dan Lavu 2015-09-22 16:31:09 UTC
Verified, testing against sssd-client-1.13.0-29.el7.x86_64. 

[root@sssd1-13-0-29 ~]# cat /etc/sssd/sssd.conf 

domains = sssdad2012r2.com
config_file_version = 2
services = nss, pam

ad_domain = sssdad2012r2.com
krb5_realm = SSSDAD2012R2.COM
realmd_tags = manages-system joined-with-adcli 
cache_credentials = True
id_provider = ad
krb5_store_password_if_offline = True
default_shell = /bin/bash
ldap_id_mapping = True
use_fully_qualified_names = True
fallback_homedir = /home/%u@%d
access_provider = ad
ad_site = fedora
debug_level = 0xfff0 

All requests are going to schrodinger which is the AD server in that site.
15:25:08.210486 IP heisenbug.sssdad2012r2.com.kerberos > sssd1-13-0-29.sssdad2012r2.com.35049: Flags [.], ack 1779, win 514, options [nop,nop,TS val 6041199 ecr 59890869], length 0
15:25:08.210492 IP heisenbug.sssdad2012r2.com.kerberos > sssd1-13-0-29.sssdad2012r2.com.35049: Flags [R.], seq 1765, ack 1779, win 0, length 0
15:25:37.319579 IP sssd1-13-0-29.sssdad2012r2.com.38347 > schrodinger.sssdad2012r2.com.kerberos:  v5
15:25:37.319945 IP schrodinger.sssdad2012r2.com.kerberos > sssd1-13-0-29.sssdad2012r2.com.38347: 
15:25:37.320150 IP sssd1-13-0-29.sssdad2012r2.com.52557 > schrodinger.sssdad2012r2.com.kerberos:  v5
15:25:37.320635 IP schrodinger.sssdad2012r2.com.kerberos > sssd1-13-0-29.sssdad2012r2.com.52557: 
15:25:37.320781 IP sssd1-13-0-29.sssdad2012r2.com.50706 > schrodinger.sssdad2012r2.com.kerberos: Flags [S], seq 3325955106, win 29200, options [mss 1460,sackOK,TS val 59919980 ecr 0,nop,wscale 7], length 0

Changing the sites.
15:25:07.904798 IP sssd1-13-0-29.sssdad2012r2.com.51151 > heisenbug.sssdad2012r2.com.kerberos:  v5
15:25:07.906046 IP heisenbug.sssdad2012r2.com.kerberos > sssd1-13-0-29.sssdad2012r2.com.51151: 
15:25:07.906334 IP sssd1-13-0-29.sssdad2012r2.com.50469 > heisenbug.sssdad2012r2.com.kerberos:  v5
15:25:07.907092 IP heisenbug.sssdad2012r2.com.kerberos > sssd1-13-0-29.sssdad2012r2.com.50469: 
15:25:07.907218 IP sssd1-13-0-29.sssdad2012r2.com.35047 > heisenbug.sssdad2012r2.com.kerberos: Flags [S], seq 998764056, win 29200, options [mss 1460,sackOK,TS val 59890566 ecr 0,nop,wscale 7], length 0

All requests are going to heisenbug which is in the Default_Site.

Comment 10 errata-xmlrpc 2015-11-19 11:35:06 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.