RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Bug 1561584 - RFE: Does it make sense to remove [domain_realm] section from ipa-client krb5.conf files?
Summary: RFE: Does it make sense to remove [domain_realm] section from ipa-client krb5...
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat Enterprise Linux 8
Classification: Red Hat
Component: ipa
Version: 8.0
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: rc
: ---
Assignee: IPA Maintainers
QA Contact: ipa-qe
URL:
Whiteboard:
Depends On:
Blocks: 1644708 1647919
TreeView+ depends on / blocked
 
Reported: 2018-03-28 14:48 UTC by Brian J. Atkisson
Modified: 2023-12-15 16:05 UTC (History)
12 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2020-07-09 12:52:40 UTC
Type: Bug
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker FREEIPA-10643 0 None None None 2023-12-15 16:05:35 UTC

Description Brian J. Atkisson 2018-03-28 14:48:07 UTC
Description of problem:

The presence of a [domain_realm] profile mapping in /etc/krb5.conf prevents DNS-based kerberos referrals from working. As IdM starts supporting realm trust, it probably makes sense to not populate [domain_realm] by default, pushing clients to perform DNS realm lookups (_kerberos TXT record for realm).

Comment 5 Florence Blanc-Renaud 2018-07-10 09:11:28 UTC
Upstream ticket:
https://pagure.io/freeipa/issue/7631

Comment 17 Alexander Bokovoy 2019-03-24 07:32:03 UTC
Based on our discussions with Robbie and others, I published an article explaining a situation with Kerberos service translation and what we need to update in MIT Kerberos to allow administrators to control name resolution order on the clients: https://vda.li/en/posts/2019/03/24/Kerberos-host-to-realm-translation/

Comment 18 Brian J. Atkisson 2019-03-24 20:57:58 UTC
(In reply to Alexander Bokovoy from comment #17)
> Based on our discussions with Robbie and others, I published an article
> explaining a situation with Kerberos service translation and what we need to
> update in MIT Kerberos to allow administrators to control name resolution
> order on the clients:
> https://vda.li/en/posts/2019/03/24/Kerberos-host-to-realm-translation/

Great article! This is very helpful for explaining the situation to our users.

Comment 20 Petr Čech 2020-07-09 12:52:40 UTC
Thank you taking your time and submitting this request for Red Hat Enterprise Linux. It was unfortunately not given priority Red Hat Enterprise Linux.
Given that this request is not planned for a close release, it is highly unlikely it will be fixed in this major version of Red Hat Enterprise Linux. We are therefore closing the request as WONTFIX.
To request that Red Hat reconsiders the decision, please reopen the Bugzilla with the help of Red Hat Customer Service and provide additional business and/or technical details about it's importance to you.


Note You need to log in before you can comment on or make changes to this bug.