Bug 1442375 - squid helper squid_kerb_ldap not included in package
Summary: squid helper squid_kerb_ldap not included in package
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: squid
Version: 24
Hardware: Unspecified
OS: Linux
unspecified
low
Target Milestone: ---
Assignee: Luboš Uhliarik
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: 1452200
TreeView+ depends on / blocked
 
Reported: 2017-04-14 12:09 UTC by bpk678
Modified: 2017-05-18 14:23 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
: 1452200 (view as bug list)
Environment:
Last Closed: 2017-04-18 14:25:37 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description bpk678 2017-04-14 12:09:26 UTC
Description of problem: the external_acl helper kerberos_ldap_group or squid_kerb_ldap object is not compiled and packaged with squid, even though other helpers (LDAP_group or ext_ldap_group_acl) are.


Version-Release number of selected component (if applicable): 3.5.20


How reproducible: very


Steps to Reproduce:
1. install squid rpm package
2. review contents of /usr/lib64/squid
3. note, negotiate_kerberos_auth is not the helper in question here

Actual results: no helper object kerberos_ldap_group or squid_kerb_ldap is present.


Expected results: helper object kerberos_ldap_group or squid_kerb_ldap is present.


Additional info: not sure if this is a packaging decision, as opposed to a bug, but reporting it here.  the helper object in question furthers squid's integration with LDAP by leveraging the same Kerberos keytab used to authenticate users, and binding to LDAP with it to perform authorization based on group membership.  because the keytab is used, security is improved because no password exists in plain text on the filesystem.  the helper is included in the source code package, but not compiled and packaged with the binary package.

Comment 1 Luboš Uhliarik 2017-04-18 14:25:37 UTC
Added kerberos_ldap_group to --enable-external-acl-helpers configure option. 

Fixed in RAWHIDE.


Note You need to log in before you can comment on or make changes to this bug.