Bug 1480118 - Tracker bug -- 7.4.1 respin of sssd-docker
Tracker bug -- 7.4.1 respin of sssd-docker
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: sssd-docker (Show other bugs)
7.4
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: SSSD Maintainers
sssd-qe
: Extras, Tracking
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2017-08-10 04:29 EDT by Lukas Slebodnik
Modified: 2017-09-05 07:37 EDT (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2017-09-05 07:37:52 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Lukas Slebodnik 2017-08-10 04:29:06 EDT
Tracking rebuild of sssd-docker.
Comment 5 Niranjan Mallapadi Raghavender 2017-08-31 01:11:05 EDT
Versions:
---------
 ● rhel-atomic-host-ostree:rhel-atomic-host/7/x86_64/standard
   Version: 7.4.1 (2017-08-30 19:29:56)
   Commit: e83c16780259c5272684221e2a6007300d94bbfdc5432f9ab6025300f447145b

sssd-docker-7.4-9


Tests:

sssd-docker as Application Container: Sanity:

IDM-SSSD-TC: SSSD-App-Container: Create a sssd application container on Atomic host	1 min 34 sec	Passed
IDM-SSSD-TC: SSSD-App-Container: Query AD users using ID command from sssd app container	1 min 51 sec	Passed
IDM-SSSD-TC: SSSD-App-Container: Spawn sssd app container using realm join with adcli option	51 sec	Passed
IDM-SSSD-TC: SSSD-App-Container: Verify sssd application container runs as unprivileged	1 min 42 sec	Passed
IDM-SSSD-TC: SSSD-App-Container: kinit as AD User from sssd app container should be successfull	1 min 40 sec	Passed


sssd-docker as System Container: Sanity:

IDM-SSSD-TC: SSSD-System-Container: Deny specific ad user login to Atomic host	2 min 37 sec	Passed
IDM-SSSD-TC: SSSD-System-Container: Discover Windows Domain on atomic host using realm cli	30 sec	Passed
IDM-SSSD-TC: SSSD-System-Container: Disjoin Atomic host from AD Domain using realm leave Cli	1 min 3 sec	Passed
IDM-SSSD-TC: SSSD-System-Container: Join AD Domain using adcli as membership-software	50 sec	Passed
IDM-SSSD-TC: SSSD-System-Container: Permit specific ad user login to Atomic host	2 min 11 sec	Passed
IDM-SSSD-TC: SSSD-System-Container: Query AD user using id command from new container	2 min 5 sec	Passed
IDM-SSSD-TC: SSSD-System-Container: Query AD users using ID command	1 min 47 sec	Passed
IDM-SSSD-TC: SSSD-System-Container: Realm join with membership software samba	1 min 44 sec	Passed
IDM-SSSD-TC: SSSD-System-Container: Verify sssd selinux label	1 min 40 sec	Passed
IDM-SSSD-TC: SSSD-System-Container: Verify uninstall container leaves domain	57 sec	Passed
Comment 7 Niranjan Mallapadi Raghavender 2017-08-31 02:02:13 EDT
sssd-docker as Application Container (KCM Tests)

IDM-SSSD-TC: SSSD-App-Container: Access user secrets using KCM responder URI	2 min 7 sec	Fixed
IDM-SSSD-TC: SSSD-App-Container: Create multiple sssd application containers	3 min 33 sec	Passed (Manually Tested)
IDM-SSSD-TC: SSSD-App-Container: KCM socket should auto start secrets socket	2 min 7 sec	Passed
IDM-SSSD-TC: SSSD-App-Container: Share KCM Credential cache with other containers	2 min 30 sec	Fixed
IDM-SSSD-TC: SSSD-App-Container: Verify ccname type is KCM in sssd application container	2 min 8 sec	Passed
IDM-SSSD-TC: SSSD-App-Container: Verify sssd kcm socket	2 min 17 sec	Passed
Comment 9 Nikhil Dehadrai 2017-08-31 10:54:48 EDT
Tested bug w.r.t IPA.

Testing with new image: 4.5.0.10:
-------------------------------------
IPA server : ipa-server-4.5.0-21.el7_4.1.2.x86_64
IPA-Client Version: ipa-client-4.5.0-21.el7_4.1.2.x86_64
sssd-container image: sssd-docker-7.4.9
ipa-docker-image:  ipa-server-docker-4.5.0-10

-bash-4.2# atomic host status
State: idle
Deployments:
● atomic-host:rhel-atomic-host/7/x86_64/standard
                Version: 7.4.1 (2017-08-30 19:29:56)
                 Commit: e83c16780259c5272684221e2a6007300d94bbfdc5432f9ab6025300f447145b

Verified the bug with following scenarios:
1. Verified that IPA-client is installed through sssd-container image against ipa-docker IPA server.(type1)
2. Verified that IPA-client is installed through sssd-container image against ipa-docker IPA server.(type2)
2. Verified that klist works when ipa-client is configured with sssd-container image.
3. Verified that ipa-user/ windows AD user details can be viewed from client machine.
4. Verified that SSH works when IPA-client is configured with sssd-container image.
5. Verified that latest version of ipa-client is available with sssd-container image.
6. Verified that IPA-client can be uninstalled.
7. Verified that IPA-client is installed through sssd-container(type1) image against RHEL ipa-server.
8. Verified that IPA-client is installed through sssd-container(type1) image against RHEL ipa-server.
Comment 12 Nikhil Dehadrai 2017-09-04 04:59:23 EDT
Based on above observations in Comment#5, Comment#7, Comment#9 and Comment#11, marking the status of bug to "VERIFIED"
Comment 14 errata-xmlrpc 2017-09-05 07:37:52 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2017:2615

Note You need to log in before you can comment on or make changes to this bug.