Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1603058 - AD authentication failing cross region.
AD authentication failing cross region.
Status: CLOSED ERRATA
Product: Red Hat CloudForms Management Engine
Classification: Red Hat
Component: Replication (Show other bugs)
5.9.0
Unspecified Unspecified
medium Severity medium
: GA
: 5.9.4
Assigned To: Joe Vlcek
Mike Shriver
auth:miqldap:ad
: ZStream
Depends On: 1594641
Blocks:
  Show dependency treegraph
 
Reported: 2018-07-19 00:27 EDT by Satoe Imaishi
Modified: 2018-09-04 14:02 EDT (History)
10 users (show)

See Also:
Fixed In Version: 5.9.4.1
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: 1594641
Environment:
Last Closed: 2018-09-04 14:01:40 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: CFME Core


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Knowledge Base (Solution) 3525081 None None None 2018-07-19 00:27 EDT
Red Hat Product Errata RHSA-2018:2561 None None None 2018-09-04 14:02 EDT

  None (edit)
Comment 2 CFME Bot 2018-07-19 09:20:48 EDT
New commit detected on ManageIQ/manageiq/gaprindashvili:

https://github.com/ManageIQ/manageiq/commit/5fa5d3c700ec00e2b96d45b5dc81f10f442abb68
commit 5fa5d3c700ec00e2b96d45b5dc81f10f442abb68
Author:     Alberto Bellotti <abellotti@users.noreply.github.com>
AuthorDate: Tue Jul 17 13:50:30 2018 -0400
Commit:     Alberto Bellotti <abellotti@users.noreply.github.com>
CommitDate: Tue Jul 17 13:50:30 2018 -0400

    Merge pull request #17690 from jvlcek/bz_1594641_ad_upn

    Force user_type to UPN when username is a UPN
    (cherry picked from commit c14bb2cd97ef584a70f34434245ec53c50b2418f)

    Fixes https://bugzilla.redhat.com/show_bug.cgi?id=1603058

 lib/miq_ldap.rb | 22 +-
 spec/lib/miq_ldap_spec.rb | 61 +
 2 files changed, 77 insertions(+), 6 deletions(-)
Comment 5 Mike Shriver 2018-08-08 14:36:58 EDT
Tested in CFME 5.9.4.2.20180802030318_f91df08

I configured two CFME regions, with Appliance A as global, and Appliance B as remote replication partners.

I configured LDAP auth with an AD server and SAM Account Name user type, on both Appliance A and Appliance B.

I configured a catalog item and catalog to order through service requests.

This service order was successful while logged in as an AD SAM account user on both Appliance A and Appliance B, a cross-region service order as described in the original BZ comment.
Comment 7 errata-xmlrpc 2018-09-04 14:01:40 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2018:2561

Note You need to log in before you can comment on or make changes to this bug.