Bug 1168735
| Summary: | The Kerberos provider is not properly views-aware | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Jakub Hrozek <jhrozek> |
| Component: | sssd | Assignee: | Sumit Bose <sbose> |
| Status: | CLOSED ERRATA | QA Contact: | Kaushik Banerjee <kbanerje> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | medium | ||
| Version: | 7.1 | CC: | grajaiya, jgalipea, jherrman, jhrozek, lslebodn, mkosek, mnavrati, mzidek, nsoman, pbrezina, preichl, sgoveas, sssd-maint |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | sssd-1.12.2-32.el7 | Doc Type: | Bug Fix |
| Doc Text: |
The following known issue description has been removed from the RHEL 7.1 Beta Release Notes:
The Kerberos provider of SSSD does not take into account that UIDs can be overridden with the views functionality, which is new in Red Hat Enterprise Linux 7.1. In addition, if a user has his UID overridden, the original UID is used instead. Consequently, using an incorrect UID can, for example, cause failures when creating the Kerberos keyring cache. No workaround is available at the moment.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2015-03-05 10:34:33 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 1168850 | ||
|
Description
Jakub Hrozek
2014-11-27 17:09:30 UTC
Upstream ticket: https://fedorahosted.org/sssd/ticket/2510 Fixed in master: * b7088215501c99e40ae71d1c57e0b789bbae2c87 * 2bf1cbffaac3b4bc0bd736493c985ca865092805 * 61d2ccf1dae3f1e7fc987ae98cb5c493cc73a782 Verified in version
[root@sideswipe ~]# rpm -q sssd ipa-server
sssd-1.12.2-52.el7.x86_64
ipa-server-4.1.0-17.el7.x86_64
On Server
[root@sideswipe ~]# ipa idoverrideuser-add 'default trust view' aduser1 --uid 1672600010
------------------------------------------
Added User ID override "aduser1"
------------------------------------------
Anchor to override: aduser1
UID: 1672600010
[root@sideswipe ~]# service sssd stop; rm -rf /var/lib/sss/{db,mc}/*; service sssd start
On Client
[root@ratchet ~]# service sssd stop; rm -rf /var/lib/sss/{db,mc}/*; service sssd start
[root@ratchet ~]# ssh -l aduser1 `hostname` "id;klist"
aduser1@ratchet.ipabugs.test's password:
Could not chdir to home directory /home/adtest.qe/aduser1: Permission denied
uid=1672600010(aduser1) gid=1148401313(aduser1) groups=1148401313(aduser1),1148400513(domain users),1148401449(adgroup1),1148402424(adunigroup1),1148402425(adgroup2),1672600004(sudogroup) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
Ticket cache: KEYRING:persistent:1672600010:krb_ccache_QCg9JGw
Default principal: aduser1
Valid starting Expires Service principal
01/28/2015 19:43:32 01/29/2015 05:43:32 krbtgt/ADTEST.QE
renew until 01/29/2015 19:43:32
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2015-0441.html |