RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Bug 1349882 - sssd does not work under non-root user
Summary: sssd does not work under non-root user
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: sssd
Version: 7.3
Hardware: All
OS: Linux
medium
medium
Target Milestone: beta
: ---
Assignee: Petr Čech
QA Contact: Steeve Goveas
URL:
Whiteboard:
Depends On:
Blocks: 1256920
TreeView+ depends on / blocked
 
Reported: 2016-06-24 12:47 UTC by Miroslav Vadkerti
Modified: 2020-05-02 18:23 UTC (History)
9 users (show)

Fixed In Version: sssd-1.14.0-6.el7
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
: 1578014 (view as bug list)
Environment:
Last Closed: 2016-11-04 07:19:19 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github SSSD sssd issues 4110 0 None closed sssd does not work under non-root user 2021-01-18 18:36:20 UTC
Red Hat Product Errata RHEA-2016:2476 0 normal SHIPPED_LIVE sssd bug fix and enhancement update 2016-11-03 14:08:11 UTC

Description Miroslav Vadkerti 2016-06-24 12:47:11 UTC
Description of problem:
When we try to start sssd with:

[sssd]
user = sssd

The daemon does not start. I can see this in journal:

Jun 24 13:33:58 cc-vtoe13b.lab.eng.brq.redhat.com sssd[23367]: Exiting the SSSD. Could not restart critical service [ssh].
Jun 24 13:33:58 cc-vtoe13b.lab.eng.brq.redhat.com systemd[1]: sssd.service: control process exited, code=exited status=1

More interesting stuff is in sssd_cctest.com.log (with level 4):

(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [be_res_get_opts] (0x0100): Lookup order: ipv4_first  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [recreate_ares_channel] (0x0100): Initializing new c-ares channel  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [monitor_common_send_id] (0x0100): Sending ID: (%BE_cctest.com,1)  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [sss_names_init_from_args] (0x0100): Using re [(((?P<domain>[^\\]+)\\(?P<name>.+$))|((?P<name>[^@]+)@(?P<domain>.+$))|(^(?P<name>[^@\\]+)$))].  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [sss_fqnames_init] (0x0100): Using fq format [%1$s@%2$s].  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [dp_load_configuration] (0x0100): Using [ipa] provider for [id]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [dp_load_configuration] (0x0100): Using [ipa] provider for [auth]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [dp_load_configuration] (0x0100): Using [ipa] provider for [access]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [dp_load_configuration] (0x0100): Using [ipa] provider for [chpass]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [dp_load_configuration] (0x0100): Using [ipa] provider for [sudo]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [dp_load_configuration] (0x0100): Using [ipa] provider for [autofs]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [dp_load_configuration] (0x0100): Using [ipa] provider for [selinux]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [dp_load_configuration] (0x0100): Using [ipa] provider for [hostid]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [dp_load_configuration] (0x0100): Using [ipa] provider for [subdomains]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [common_parse_search_base] (0x0100): Search base added: [DEFAULT][cn=accounts,dc=cctest][SUBTREE][]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [sdap_set_sasl_options] (0x0100): Will look for cc-vtoe13b.lab.eng.brq.redhat.com@CCTEST in default keytab  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [sdap_set_sasl_options] (0x0100): Option ldap_sasl_authid set to host/cc-vtoe13b.lab.eng.brq.redhat.com  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [sdap_set_sasl_options] (0x0100): Option ldap_sasl_realm set to CCTEST  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [common_parse_search_base] (0x0100): Search base added: [USER][cn=accounts,dc=cctest][SUBTREE][]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [common_parse_search_base] (0x0100): Search base added: [GROUP][cn=accounts,dc=cctest][SUBTREE][]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [common_parse_search_base] (0x0100): Search base added: [NETGROUP][cn=ng,cn=alt,dc=cctest][SUBTREE][]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [ipa_get_id_options] (0x0100): Option ipa_host_search_base set to cn=accounts,dc=cctest  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [common_parse_search_base] (0x0100): Search base added: [IPA_HOST][cn=accounts,dc=cctest][SUBTREE][]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [common_parse_search_base] (0x0100): Search base added: [IPA_HBAC][cn=hbac,dc=cctest][SUBTREE][]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [ipa_get_id_options] (0x0100): Option ipa_selinux_search_base set to cn=selinux,dc=cctest  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [common_parse_search_base] (0x0100): Search base added: [IPA_SELINUX][cn=selinux,dc=cctest][SUBTREE][]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [common_parse_search_base] (0x0100): Search base added: [SERVICE][cn=accounts,dc=cctest][SUBTREE][]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [ipa_get_id_options] (0x0100): Option ipa_subdomains_search_base set to cn=trusts,dc=cctest  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [common_parse_search_base] (0x0100): Search base added: [IPA_SUBDOMAINS][cn=trusts,dc=cctest][SUBTREE][]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [ipa_get_id_options] (0x0100): Option ipa_master_domain_search_base set to cn=ad,cn=etc,dc=cctest  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [common_parse_search_base] (0x0100): Search base added: [IPA_MASTER_DOMAIN][cn=ad,cn=etc,dc=cctest][SUBTREE][]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [ipa_get_id_options] (0x0100): Option ipa_ranges_search_base set to cn=ranges,cn=etc,dc=cctest  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [common_parse_search_base] (0x0100): Search base added: [IPA_RANGES][cn=ranges,cn=etc,dc=cctest][SUBTREE][]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [ipa_get_id_options] (0x0100): Option ipa_views_search_base set to cn=views,cn=accounts,dc=cctest  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [common_parse_search_base] (0x0100): Search base added: [IPA_VIEWS][cn=views,cn=accounts,dc=cctest][SUBTREE][]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [ipa_init_dyndns] (0x0100): Dynamic DNS updates are of.  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [krb5_try_kdcip] (0x0100): No KDC found in configuration, trying legacy option  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [ipa_get_auth_options] (0x0100): Option krb5_fast_principal set to host/cc-vtoe13b.lab.eng.brq.redhat.com@CCTEST  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [ipa_get_auth_options] (0x0100): Option krb5_use_kdcinfo set to true  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [check_and_export_options] (0x0100): No KDC explicitly configured, using defaults.  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [check_and_export_options] (0x0100): No kpasswd server explicitly configured, using the KDC or defaults.  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [common_parse_search_base] (0x0100): Search base added: [AUTOFS][cn=default,cn=automount,dc=cctest][SUBTREE][]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [fo_resolve_service_send] (0x0100): Trying to resolve service 'IPA'  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [resolv_getsrv_send] (0x0100): Trying to resolve SRV record of '_ldap._tcp.cctest.com'  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [id_callback] (0x0100): Got id ack and version (1) from Monitor  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [resolv_discover_srv_done] (0x0040): SRV query failed [4]: Domain name not found  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [fo_set_port_status] (0x0100): Marking port 0 of server '(no name)' as 'not working'  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [resolve_srv_done] (0x0040): Unable to resolve SRV [1432158233]: SRV record not found  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [set_srv_data_status] (0x0100): Marking SRV lookup of service 'IPA' as 'not resolved'  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [be_resolve_server_process] (0x0080): Couldn't resolve server (SRV lookup meta-server), resolver returned [1432158233]: SRV record not found  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [fo_resolve_service_send] (0x0100): Trying to resolve service 'IPA'  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [resolv_gethostbyname_files_send] (0x0100): Trying to resolve A record of 'cc-ipa.lab.eng.brq.redhat.com' in files  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [set_server_common_status] (0x0100): Marking server 'cc-ipa.lab.eng.brq.redhat.com' as 'resolving name'  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [resolv_gethostbyname_files_send] (0x0100): Trying to resolve AAAA record of 'cc-ipa.lab.eng.brq.redhat.com' in files  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [resolv_gethostbyname_dns_query] (0x0100): Trying to resolve A record of 'cc-ipa.lab.eng.brq.redhat.com' in DNS  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [set_server_common_status] (0x0100): Marking server 'cc-ipa.lab.eng.brq.redhat.com' as 'name resolved'  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [sdap_set_search_base] (0x0100): Setting option [ldap_sudo_search_base] to [dc=cctest].  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [common_parse_search_base] (0x0100): Search base added: [SUDO][dc=cctest][SUBTREE][]  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [fo_resolve_service_send] (0x0100): Trying to resolve service 'IPA'  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [child_sig_handler] (0x0100): child [23406] finished successfully.  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [sdap_cli_auth_step] (0x0100): expire timeout is 900  
(Fri Jun 24 13:39:21 2016) [sssd[be[cctest.com]]] [sasl_bind_send] (0x0100): Executing sasl bind mech: GSSAPI, user: host/cc-vtoe13b.lab.eng.brq.redhat.com  
(Fri Jun 24 13:39:22 2016) [sssd[be[cctest.com]]] [fo_set_port_status] (0x0100): Marking port 0 of server 'cc-ipa.lab.eng.brq.redhat.com' as 'working'  
(Fri Jun 24 13:39:22 2016) [sssd[be[cctest.com]]] [set_server_common_status] (0x0100): Marking server 'cc-ipa.lab.eng.brq.redhat.com' as 'working'  
(Fri Jun 24 13:39:22 2016) [sssd[be[cctest.com]]] [be_run_online_cb] (0x0080): Going online. Running callbacks.  
(Fri Jun 24 13:39:22 2016) [sssd[be[cctest.com]]] [sysdb_range_create] (0x0040): Invalid range, skipping. Expected that either the secondary base RID or the SID of the trusted domain is set, but not both or none of them.  
(Fri Jun 24 13:39:22 2016) [sssd[be[cctest.com]]] [sss_write_krb5_localauth_snippet] (0x0040): creating the temp file [/var/lib/sss/pubconf/krb5.include.d/localauth_pluginj9HtDC] for domain-realm mappings failed.  
                                                                                                                                                                                                                   (Fri Jun 24 13:39:22 2016) [sssd[be[cctest.com]]] [sss_write_krb5_localauth_snippet] (0x0080): Could not remove file [/var/lib/sss/pubconf/krb5.include.d/localauth_pluginj9HtDC]: [2]: No such file or directory  
(Fri Jun 24 13:39:22 2016) [sssd[be[cctest.com]]] [sss_write_krb5_conf_snippet] (0x0040): sss_write_krb5_localauth_snippet failed.  
(Fri Jun 24 13:39:22 2016) [sssd[be[cctest.com]]] [sss_krb5_touch_config] (0x0020): Unable to change mtime of "/etc/krb5.conf" [13]: Permission denied  
(Fri Jun 24 13:39:22 2016) [sssd[be[cctest.com]]] [sss_write_krb5_conf_snippet] (0x0020): Unable to change last modification time of krb5.conf. Created mappings may not be loaded.
(Fri Jun 24 13:39:22 2016) [sssd[be[cctest.com]]] [ipa_subdom_reinit] (0x0080): sss_write_krb5_conf_snippet failed.
(Fri Jun 24 13:39:22 2016) [sssd[be[cctest.com]]] [sss_write_domain_mappings] (0x0040): creating the temp file [/var/lib/sss/pubconf/krb5.include.d/domain_realm_cctest_comF6IolL] for domain-realm mappings failed.
                                                                                                                                                                                                                   (Fri Jun 24 13:39:22 2016) [sssd[be[cctest.com]]] [sss_krb5_touch_config] (0x0020): Unable to change mtime of "/etc/krb5.conf" [13]: Permission denied
(Fri Jun 24 13:39:22 2016) [sssd[be[cctest.com]]] [sss_write_domain_mappings] (0x0020): Unable to change last modification time of krb5.conf. Created mappings may not be loaded.
(Fri Jun 24 13:39:22 2016) [sssd[be[cctest.com]]] [sss_write_domain_mappings] (0x0080): Could not remove file [/var/lib/sss/pubconf/krb5.include.d/domain_realm_cctest_comF6Iol�]: [2]: No such file or directory
(Fri Jun 24 13:39:22 2016) [sssd[be[cctest.com]]] [ipa_subdom_reinit] (0x0080): sss_krb5_write_mappings failed.
(Fri Jun 24 13:39:22 2016) [sssd[be[cctest.com]]] [be_ptask_enable] (0x0080): Task [Subdomains Refresh]: already enabled

Version-Release number of selected component (if applicable):
sssd-ipa-1.14.0-0.1.alpha.el7.x86_64
sssd-krb5-common-1.14.0-0.1.alpha.el7.x86_64  
sssd-common-1.14.0-0.1.alpha.el7.x86_64
sssd-client-1.14.0-0.1.alpha.el7.x86_64  
sssd-common-pac-1.14.0-0.1.alpha.el7.x86_64

How reproducible:
100%

Steps to Reproduce:
1. Setup sssd for an IPA server (via ipa_client)
2. Set user=sssd in sssd.conf [sssd] section
3. Restart sssd

Actual results:
sssd does not start

Expected results:
sssd works as in RHEL7.2

Additional info:
This is an regression. I do not think this has anything to do with out IPA server's config running currently on RHEL7.2. We can provide test machine for reference if needed. We are able to test this concrete bug but we cannot provide extended testing of sssd itself.

Comment 1 Jakub Hrozek 2016-06-27 08:45:48 UTC
Petr will take a look and try to reproduce.

Comment 6 Jakub Hrozek 2016-07-01 13:50:59 UTC
Upstream ticket:
https://fedorahosted.org/sssd/ticket/3077

Comment 9 Lukas Slebodnik 2016-07-12 16:49:54 UTC
master:
* 75dead699a19dda7d8dfca89e2f97efbf0c264a2

Comment 15 errata-xmlrpc 2016-11-04 07:19:19 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHEA-2016-2476.html


Note You need to log in before you can comment on or make changes to this bug.