Bug 1452200 - Include kerberos_ldap_group helper in squid
Summary: Include kerberos_ldap_group helper in squid
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: squid
Version: 7.4
Hardware: All
OS: Linux
Target Milestone: rc
: ---
Assignee: Luboš Uhliarik
QA Contact: Jan Houska
Lenka Špačková
Depends On: 1442375
Blocks: 1420851 1465904 1466370
TreeView+ depends on / blocked
Reported: 2017-05-18 14:23 UTC by Nilesh Parmar
Modified: 2020-06-11 13:51 UTC (History)
14 users (show)

Fixed In Version: squid-3.5.20-11.el7
Doc Type: Release Note
Doc Text:
The _squid_ packages now provide the `kerberos_ldap_group` helper This update adds the `kerberos_ldap_group` external Access Control Lists (ACL) helper to the _squid_ packages. The `kerberos_ldap_group` helper is a reference implementation that supports Simple Authentication and Security Layer (SASL) and Generic Security Services API (GSSAPI) authentication to an LDAP server, intended primarily to connect to Active Directory or OpenLDAP-based LDAP servers.
Clone Of: 1442375
Last Closed: 2018-04-10 14:44:55 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2018:0825 0 None None None 2018-04-10 14:45:12 UTC

Description Nilesh Parmar 2017-05-18 14:23:06 UTC
+++ This bug was initially created as a clone of Bug #1442375 +++

Description of problem: the external_acl helper kerberos_ldap_group or squid_kerb_ldap object is not compiled and packaged with squid, even though other helpers (LDAP_group or ext_ldap_group_acl) are.

Version-Release number of selected component (if applicable): 3.5.20

How reproducible: very

Steps to Reproduce:
1. install squid rpm package
2. review contents of /usr/lib64/squid
3. note, negotiate_kerberos_auth is not the helper in question here

Actual results: no helper object kerberos_ldap_group or squid_kerb_ldap is present.

Expected results: helper object kerberos_ldap_group or squid_kerb_ldap is present.

Additional info: not sure if this is a packaging decision, as opposed to a bug, but reporting it here.  the helper object in question furthers squid's integration with LDAP by leveraging the same Kerberos keytab used to authenticate users, and binding to LDAP with it to perform authorization based on group membership.  because the keytab is used, security is improved because no password exists in plain text on the filesystem.  the helper is included in the source code package, but not compiled and packaged with the binary package.

--- Additional comment from Luboš Uhliarik on 2017-04-18 10:25:37 EDT ---

Added kerberos_ldap_group to --enable-external-acl-helpers configure option. 

Fixed in RAWHIDE.

Comment 2 Nilesh Parmar 2017-05-18 14:24:12 UTC
Add kerberos_ldap_group to --enable-external-acl-helpers configure option

Comment 16 errata-xmlrpc 2018-04-10 14:44:55 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.