Bug 1458920
| Summary: | RHV-M fails to authenticate against IPA when using custom socket factory and STARTTLS | ||||||
|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Virtualization Manager | Reporter: | Wolfram Richter <wrichter> | ||||
| Component: | ovirt-engine-extension-aaa-ldap | Assignee: | Martin Perina <mperina> | ||||
| Status: | CLOSED DUPLICATE | QA Contact: | Gonza <grafuls> | ||||
| Severity: | unspecified | Docs Contact: | |||||
| Priority: | unspecified | ||||||
| Version: | 4.1.1 | CC: | bazulay, lsurette, oourfali, Rhev-m-bugs, wrichter, ykaul | ||||
| Target Milestone: | --- | ||||||
| Target Release: | --- | ||||||
| Hardware: | Unspecified | ||||||
| OS: | Unspecified | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2017-06-06 17:37:31 UTC | Type: | Bug | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | Integration | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Attachments: |
|
||||||
This issue has been discussed and analysed on the rhea-tech mailing list: http://post-office.corp.redhat.com/archives/rhev-tech/2017-May/msg00323.html Wolfram, do you plan to attach customer ticket to this downstream bug? If not then I'd like to close this downstream bug as a duplicate for upstream BZ1456352 ... Sorry I hadn't found the ticket bug that Andra had opened - let's close this one and continue the work in BZ1456352 *** This bug has been marked as a duplicate of bug 1456352 *** |
Created attachment 1285136 [details] AAA configuration Description of problem: I configured the aaa extension of ovirt-engine to authenticate against IPA via LDAP/STARTLS. While the same configuration works flawlessly in RHEV3.6, authentication does not work with RHV4.1. TCPDumping on the IPA side, I can see the SYN/SYN+ACK/ACK handshake taking place, but no other data going over the wire. Version-Release number of selected component (if applicable): ovirt-engine-4.1.1.8-0.1.el7.noarch ovirt-engine-extension-aaa-ldap-setup-1.3.1-1.el7ev.noarch How reproducible: 100% (I can provide access to an environment where this can be recreated within the Red Hat VPN). Steps to Reproduce: 1. Install IPA & RHV-M on separate VMs 2. configure authn/authz extension like the attached configurations 3. run ovirt-engine-extensions-tool --log-level=FINEST aaa search --extension-name=IPA-authz Actual results: [root@rhevm ~]# vi /etc/ovirt-engine/aaa/IPA.properties [root@rhevm ~]# egrep "startTLS|connection-options" /etc/ovirt-engine/aaa/IPA.properties pool.default.ssl.startTLS = true #pool.default.ssl.startTLS = false pool.default.connection-options.connectTimeoutMillis = 60000 pool.default.connection-options.responseTimeoutMillis = 60000 [root@rhevm ~]# systemctl restart ovirt-engine …[waited until overt-engine is initialised and login via admin UI is possible]… [root@rhevm ~]# ovirt-engine-extensions-tool --log-level=FINEST --log-file=/tmp/aaa_with_60sec_timeout.log aaa search --extension-name=IPA-authz …[skip console output]… [root@rhevm ~]# grep -i LDAPException /tmp/aaa_with_60sec_timeout.log WARNING: Exception: An error occurred while attempting to connect to server ipa.hailstorm2.coe.muc.redhat.com:389: java.io.IOException: LDAPException(resultCode=91 (connect error), errorMessage='Unable to establish a connection to server ipa.hailstorm2.coe.muc.redhat.com/192.168.101.11:389 within the configured timeout of 60000 milliseconds.') WARNING: Exception: An error occurred while attempting to connect to server ipa.hailstorm2.coe.muc.redhat.com:389: java.io.IOException: LDAPException(resultCode=91 (connect error), errorMessage='Unable to establish a connection to server ipa.hailstorm2.coe.muc.redhat.com/192.168.101.11:389 within the configured timeout of 60000 milliseconds.') WARNING: Exception: An error occurred while attempting to connect to server ipa.hailstorm2.coe.muc.redhat.com:389: java.io.IOException: LDAPException(resultCode=91 (connect error), errorMessage='Unable to establish a connection to server ipa.hailstorm2.coe.muc.redhat.com/192.168.101.11:389 within the configured timeout of 60000 milliseconds.') [root@rhevm ~]# Expected results: No timeout exceptions in the log output; authentication against LDAP works. Additional info: When disabling TLS AND reverting to the standard socket factory, the problem does not appear: pool.default.ssl.startTLS = false pool.default.socketfactory.type = java