Bug 1284813
| Summary: | ipa-otptoken-import fails on nonexistent ldap connection | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Jan Kurik <jkurik> |
| Component: | ipa | Assignee: | IPA Maintainers <ipa-maint> |
| Status: | CLOSED ERRATA | QA Contact: | Namita Soman <nsoman> |
| Severity: | urgent | Docs Contact: | |
| Priority: | urgent | ||
| Version: | 7.2 | CC: | dkupka, ekeck, ipa-maint, jcholast, jkurik, ksiddiqu, mkosek, mnavrati, pvoborni, rcritten |
| Target Milestone: | rc | Keywords: | Regression, ZStream |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | ipa-4.2.0-15.el7_2.1 | Doc Type: | Bug Fix |
| Doc Text: |
Previously, connection to LDAP was held in a singleton object and creating it locally made it available in the back end. When this behavior was changed, it was not reflected in ipa-otptoken-import. As a consequence, ipa-otptoken-import was unusable because it crashed on every run. This problem has been fixed by connecting to LDAP in back end, and ipa-otptoken-import no longer crashes.
|
Story Points: | --- |
| Clone Of: | 1284414 | Environment: | |
| Last Closed: | 2015-12-08 10:37:55 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1284414 | ||
| Bug Blocks: | |||
|
Description
Jan Kurik
2015-11-24 09:38:35 UTC
Verified using ipa-server-4.2.0-15.el7_2.3.x86_64
# ipa otptoken-find --all
--------------------
0 OTP tokens matched
--------------------
----------------------------
Number of entries returned 0
----------------------------
# cat pskc1.xml
<?xml version="1.0" encoding="UTF-8"?>
<KeyContainer Version="1.0"
Id="exampleID1"
xmlns="urn:ietf:params:xml:ns:keyprov:pskc">
<KeyPackage>
<DeviceInfo>
<Manufacturer>Manufacturer</Manufacturer>
<SerialNo>987654321</SerialNo>
<UserId>DC=example-bank,DC=net</UserId>
</DeviceInfo>
<CryptoModuleInfo>
<Id>CM_ID_001</Id>
</CryptoModuleInfo>
<Key Id="12345678"
Algorithm="urn:ietf:params:xml:ns:keyprov:pskc:hotp">
<Issuer>Issuer</Issuer>
<AlgorithmParameters>
<ResponseFormat Length="8" Encoding="DECIMAL"/>
</AlgorithmParameters>
<Data>
<Secret>
<PlainValue>MTIzNDU2Nzg5MDEyMzQ1Njc4OTA=
</PlainValue>
</Secret>
<Counter>
<PlainValue>0</PlainValue>
</Counter>
</Data>
<UserId>UID=jsmith,DC=example-bank,DC=net</UserId>
</Key>
</KeyPackage>
</KeyContainer>
# ipa-otptoken-import pskc1.xml result.xml
Added token: 12345678
The ipa-otptoken-import command was successful
# cat result.xml
<KeyContainer xmlns="urn:ietf:params:xml:ns:keyprov:pskc" Version="1.0" Id="exampleID1">
</KeyContainer>
# ipa otptoken-find --all
-------------------
1 OTP token matched
-------------------
dn: ipatokenuniqueid=12345678,cn=otp,dc=testrelm,dc=test
Unique ID: 12345678
Type: HOTP
Owner: admin
Manager: admin
Vendor: Manufacturer
Serial: 987654321
Key: MTIzNDU2Nzg5MDEyMzQ1Njc4OTA=
Algorithm: sha1
Digits: 8
Counter: 0
objectclass: ipatokenhotp, top, ipatoken
----------------------------
Number of entries returned 1
----------------------------
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2015-2562.html |