Bug 1165721 - [AAA] [KerbLDAP] propogate exceptions to engine
Summary: [AAA] [KerbLDAP] propogate exceptions to engine
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: oVirt
Classification: Retired
Component: ovirt-engine-core
Version: 3.4
Hardware: Unspecified
OS: Unspecified
unspecified
medium
Target Milestone: ---
: 3.5.1
Assignee: Yair Zaslavsky
QA Contact: Ondra Machacek
URL:
Whiteboard: infra
Depends On:
Blocks: oVirt-AAA-LDAP
TreeView+ depends on / blocked
 
Reported: 2014-11-19 14:33 UTC by Alon Bar-Lev
Modified: 2016-02-10 19:30 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2015-01-21 16:02:30 UTC
oVirt Team: Infra
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
oVirt gerrit 35339 0 master MERGED aaa: exceptions should be propagated in builtin ldap provider Never
oVirt gerrit 35346 0 ovirt-engine-3.5 MERGED aaa: exceptions should be propagated in builtin ldap provider Never

Description Alon Bar-Lev 2014-11-19 14:33:56 UTC
Subject: [PATCH] aaa: exceptions should be propagated in builtin ldap provider

All exceptions which are caught during the privileged action execution
should be propagated and not swollowed.

In addition, NegativeArraySizeException is handled as a severe exception,
meaning there will be no attempt to try the next server if is caught

Change-Id: Iafa1dcf67545e81a14981bb3c33e52a570684d72
Topic: AAA
Signed-off-by: Yair Zaslavsky <yzaslavs>

Comment 1 Ondra Machacek 2014-12-09 13:30:34 UTC
rhevm-manage-domains add --domain=brq-ipa-rh66.rhev.lab.eng.brq.redhat.com --user=vdcadmin --provider=ipa
Enter password:
Failure while testing domain brq-ipa-rh66.rhev.lab.eng.brq.redhat.com. Details: An internal error has ocurred in the Kerberos implementation of the Java virtual machine. This usually means that the LDAP server is configured with a minimum security strength factor (minssf) of 0. Change it to 1 and try again. You can also try to change the SASL quality of protection to "auth" which will lower the protection level.  To change the SASL quality of protection to "auth" use engine-config -s SASL_QOP=auth and restart engine.

Comment 2 Sandro Bonazzola 2015-01-21 16:02:30 UTC
oVirt 3.5.1 has been released. If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.