Bug 1384964 - Document how to resolve lost OTP tokens and what are the security risks of general RBAC permissions
Summary: Document how to resolve lost OTP tokens and what are the security risks of ge...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: doc-Linux_Domain_Identity_Management_Guide
Version: 7.3
Hardware: Unspecified
OS: Unspecified
medium
unspecified
Target Milestone: rc
: ---
Assignee: Marc Muehlfeld
QA Contact: Namita Soman
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-10-14 12:39 UTC by Petr Vobornik
Modified: 2019-04-09 10:31 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-04-09 10:31:38 UTC
Target Upstream Version:


Attachments (Terms of Use)

Description Petr Vobornik 2016-10-14 12:39:25 UTC
Description of problem:
This bz is based on https://fedorahosted.org/freeipa/ticket/6376 FreeIPA won't implement ticket #6376 because the RBAC permissions for help desk might depend on organization needs/structure.

Adding general "modify" permission as for other objects might cause a security risk - more on http://www.freeipa.org/page/V4/OTP#Helpdesk

A possible way to resolve lost token and what security risk a general permission might cause should be documented.

Otline, how to resolve lost token:
1. admin can enable password auth for the user
2. user can then create new otp token 
3. user can remove old token
4. admin can disable password auth

SME: Nathaniel McCallum

Comment 5 Marc Muehlfeld 2019-04-09 10:31:38 UTC
The update is now available on the Customer Portal.


Note You need to log in before you can comment on or make changes to this bug.