Bug 137613 - Kerberos 5 1.2 does not provide a writable keytab access method ("WRFILE:")
Kerberos 5 1.2 does not provide a writable keytab access method ("WRFILE:")
Status: CLOSED WONTFIX
Product: Red Hat Enterprise Linux 3
Classification: Red Hat
Component: krb5 (Show other bugs)
3.0
All Linux
medium Severity medium
: ---
: ---
Assigned To: Nalin Dahyabhai
: FutureFeature
Depends On:
Blocks: 114938 122008
  Show dependency treegraph
 
Reported: 2004-10-29 15:23 EDT by Nalin Dahyabhai
Modified: 2012-06-20 12:16 EDT (History)
0 users

See Also:
Fixed In Version:
Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2012-06-20 12:16:13 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Nalin Dahyabhai 2004-10-29 15:23:16 EDT
Description of problem:
Applications which attempt to manipulate the contents of Kerberos
keytabs need to open those files using the "WRFILE:" method in order
to have read-write access.  By default, libkrb5 provides "FILE:", but
does not "know" about the "WRFILE:" method.  Kerberos 5 1.3 allows
"WRFILE:" access to any application.

Version-Release number of selected component (if applicable):
1.2.7-27

How reproducible:
Always

Steps to Reproduce:
1. Configure Samba 3.0.6 or later with "use kerberos keytab" enabled.
2. Attempt to set up a key in the system keytab using "net ads keytab
add".
  
Actual results:
"net" will because it has attempted to call a NULL method pointer

Expected results:
"net" runs to completion

Additional info:
Samba detects if the Kerberos implementation supports WRFILE: at
compile-time, and assumes that FILE: is writable if WRFILE: is not
available.  Because this is determined at compile-time, Samba must be
recompiled to notice that the implementation supports WRFILE:.
Comment 1 Wil Cooley 2005-01-13 20:05:44 EST
For reference for others who may be looking for a solution to this
problem before this is resolved, you can add the following to your
/etc/krb5.conf:

[libdefaults]
default_keytab_name = WRFILE:/etc/krb5.keytab

and 'net ads keytab CREATE' (at least; haven't tested others) will
work as expected.
Comment 2 Jiri Pallich 2012-06-20 12:16:13 EDT
Thank you for submitting this issue for consideration in Red Hat Enterprise Linux. The release for which you requested us to review is now End of Life. 
Please See https://access.redhat.com/support/policy/updates/errata/

If you would like Red Hat to re-consider your feature request for an active release, please re-open the request via appropriate support channels and provide additional supporting details about the importance of this issue.

Note You need to log in before you can comment on or make changes to this bug.