Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1458920

Summary: RHV-M fails to authenticate against IPA when using custom socket factory and STARTTLS
Product: Red Hat Enterprise Virtualization Manager Reporter: Wolfram Richter <wrichter>
Component: ovirt-engine-extension-aaa-ldapAssignee: Martin Perina <mperina>
Status: CLOSED DUPLICATE QA Contact: Gonza <grafuls>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 4.1.1CC: bazulay, lsurette, oourfali, Rhev-m-bugs, wrichter, ykaul
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-06-06 17:37:31 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: Integration RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
AAA configuration none

Description Wolfram Richter 2017-06-05 20:38:22 UTC
Created attachment 1285136 [details]
AAA configuration

Description of problem:
I configured the aaa extension of ovirt-engine to authenticate against IPA via LDAP/STARTLS. While the same configuration works flawlessly in RHEV3.6, authentication does not work with RHV4.1. TCPDumping on the IPA side, I can see the SYN/SYN+ACK/ACK handshake taking place, but no other data going over the wire.


Version-Release number of selected component (if applicable):
ovirt-engine-4.1.1.8-0.1.el7.noarch
ovirt-engine-extension-aaa-ldap-setup-1.3.1-1.el7ev.noarch


How reproducible:
100% 
(I can provide access to an environment where this can be recreated within the Red Hat VPN).


Steps to Reproduce:
1. Install IPA & RHV-M on separate VMs
2. configure authn/authz extension like the attached configurations
3. run ovirt-engine-extensions-tool --log-level=FINEST aaa search --extension-name=IPA-authz


Actual results:

[root@rhevm ~]# vi /etc/ovirt-engine/aaa/IPA.properties
[root@rhevm ~]# egrep  "startTLS|connection-options" /etc/ovirt-engine/aaa/IPA.properties
pool.default.ssl.startTLS = true
#pool.default.ssl.startTLS = false
pool.default.connection-options.connectTimeoutMillis = 60000
pool.default.connection-options.responseTimeoutMillis = 60000
[root@rhevm ~]# systemctl restart ovirt-engine
…[waited until overt-engine is initialised and login via admin UI is possible]… 
[root@rhevm ~]# ovirt-engine-extensions-tool --log-level=FINEST --log-file=/tmp/aaa_with_60sec_timeout.log aaa search --extension-name=IPA-authz
…[skip console output]… 
[root@rhevm ~]# grep -i LDAPException /tmp/aaa_with_60sec_timeout.log
WARNING: Exception: An error occurred while attempting to connect to server ipa.hailstorm2.coe.muc.redhat.com:389:  java.io.IOException: LDAPException(resultCode=91 (connect error), errorMessage='Unable to establish a connection to server ipa.hailstorm2.coe.muc.redhat.com/192.168.101.11:389 within the configured timeout of 60000 milliseconds.')
WARNING: Exception: An error occurred while attempting to connect to server ipa.hailstorm2.coe.muc.redhat.com:389:  java.io.IOException: LDAPException(resultCode=91 (connect error), errorMessage='Unable to establish a connection to server ipa.hailstorm2.coe.muc.redhat.com/192.168.101.11:389 within the configured timeout of 60000 milliseconds.')
WARNING: Exception: An error occurred while attempting to connect to server ipa.hailstorm2.coe.muc.redhat.com:389:  java.io.IOException: LDAPException(resultCode=91 (connect error), errorMessage='Unable to establish a connection to server ipa.hailstorm2.coe.muc.redhat.com/192.168.101.11:389 within the configured timeout of 60000 milliseconds.')
[root@rhevm ~]#


Expected results:

No timeout exceptions in the log output; 
authentication against LDAP works.


Additional info:

When disabling TLS AND reverting to the standard socket factory, the problem does not appear:

pool.default.ssl.startTLS = false
pool.default.socketfactory.type = java

Comment 1 Wolfram Richter 2017-06-05 20:44:19 UTC
This issue has been discussed and analysed on the rhea-tech mailing list: http://post-office.corp.redhat.com/archives/rhev-tech/2017-May/msg00323.html

Comment 2 Martin Perina 2017-06-06 10:58:38 UTC
Wolfram, do you plan to attach customer ticket to this downstream bug? If not then I'd like to close this downstream bug as a duplicate for upstream BZ1456352 ...

Comment 3 Wolfram Richter 2017-06-06 17:37:31 UTC
Sorry I hadn't found the ticket bug that Andra had opened - let's close this one and continue the work in BZ1456352

*** This bug has been marked as a duplicate of bug 1456352 ***