Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 1726133

Summary: curl --proxy-anyauth does not sent proxy credentials
Product: Red Hat Enterprise Linux 8 Reporter: Michal Dekan <mdekan>
Component: curlAssignee: Kamil Dudka <kdudka>
Status: CLOSED WONTFIX QA Contact: Daniel Rusek <drusek>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 8.0CC: kdudka, kwalker, ptalbert
Target Milestone: rc   
Target Release: 8.0   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-08-02 15:47:36 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Comment 1 Michal Dekan 2019-07-02 08:13:46 UTC
Description of problem:

These data are coming from the customer case, so I've changed proxy credentials we are passing to the proxy server and proxy server IP address. Important is that proxy credentials are not send to the proxy server at the end:

# curl -v --proxy-anyauth --proxy-user proxy:proxy --proxy http://192.168.1.1:8080 --cacert /etc/rhsm/ca/redhat-uep.pem https://cdn.redhat.com/content/dist/rhel8/8/x86_64/appstream/os/repodata/repomd.xml --cert /etc/pki/entitlement/6636141085880603801.pem --key  /etc/pki/entitlement/6636141085880603801-key.pem
    *   Trying 192.168.1.1...
    * TCP_NODELAY set
    * Connected to 192.168.1.1 (192.168.1.1) port 8080 (#0)
    * allocate connect buffer!
    * Establish HTTP proxy tunnel to cdn.redhat.com:443
    > CONNECT cdn.redhat.com:443 HTTP/1.1
    > Host: cdn.redhat.com:443
    > User-Agent: curl/7.61.1
    > Proxy-Connection: Keep-Alive
    >
    < HTTP/1.1 407 Proxy Authentication Required
    < Proxy-Authenticate: NEGOTIATE
    < Proxy-Authenticate: NTLM
    < Proxy-Authenticate: BASIC realm="Sequence_Authentication"
    < Cache-Control: no-cache
    < Pragma: no-cache
    < Content-Type: text/html; charset=utf-8
    < Proxy-Connection: close
    < Connection: close
    < Content-Length: 1011
    <
    * Ignore 1011 bytes of response-body
    * Connect me again please
    * CONNECT phase completed!
    * Connection #0 to host 192.168.1.1 left intact
    * Found bundle for host cdn.redhat.com: 0x55afb52f8730 [serially]
    * Connection #0 isn't open enough, can't reuse
    * Hostname 192.168.1.1 was found in DNS cache
    *   Trying 192.168.1.1...
    * TCP_NODELAY set
    * Connected to 192.168.1.1 (192.168.1.1) port 8080 (#1)
    * allocate connect buffer!
    * Establish HTTP proxy tunnel to cdn.redhat.com:443
    > CONNECT cdn.redhat.com:443 HTTP/1.1
    > Host: cdn.redhat.com:443
    > User-Agent: curl/7.61.1
    > Proxy-Connection: Keep-Alive
    >
    < HTTP/1.1 407 Proxy Authentication Required
    < Proxy-Authenticate: NEGOTIATE
    * gss_init_sec_context() failed: SPNEGO cannot find mechanisms to negotiate.
    < Proxy-Authenticate: NTLM
    < Proxy-Authenticate: BASIC realm="Sequence_Authentication"
    < Cache-Control: no-cache
    < Pragma: no-cache
    < Content-Type: text/html; charset=utf-8
    < Proxy-Connection: close
    < Connection: close
    < Content-Length: 1011
    <
    * Received HTTP code 407 from proxy after CONNECT
    * CONNECT phase completed!
    * Closing connection 1
    curl: (56) Received HTTP code 407 from proxy after CONNECT

Version-Release number of selected component (if applicable):

$ cat etc/redhat-release 
Red Hat Enterprise Linux release 8.0 (Ootpa)

$ grep curl installed-rpms 
curl-7.61.1-8.el8.x86_64                                    Thu Jun 20 15:10:18 2019
libcurl-7.61.1-8.el8.x86_64                                 Thu Jun 20 15:10:18 2019


How reproducible: Unable to reproduce internally.

Actual results:

As a consequence yum repolist is failing as well:

yum repolist
Updating Subscription Management repositories.
Red Hat Enterprise Linux 8 for x86_64 - AppStream (RPMs)                        0.0  B/s |   0  B     00:00
Red Hat Enterprise Linux 8 for x86_64 - BaseOS (RPMs)                           0.0  B/s |   0  B     00:00
Failed to synchronize cache for repo 'rhel-8-for-x86_64-appstream-rpms', ignoring this repo.
Failed to synchronize cache for repo 'rhel-8-for-x86_64-baseos-rpms', ignoring this repo.

Expected results:

curl is sending proxy credentials with --proxy-anyauth

Additional info:

There is a workaround for yum, we can force basic proxy authorization:

 /etc/dnf/dnf.conf
 proxy_auth_method=basic

Comment 5 Kamil Dudka 2019-07-02 10:14:13 UTC
This is exactly the same issue as described in bug #1595260.  There is no known fix for this.  Upstream has documented it as a known issue:

https://github.com/curl/curl/commit/10c91b66#diff-b97570cc6a6d2d180356338a9ccffee0R451

Possible workarounds are:

1. Configure proxy not to advertise NTLM and NEGOTIATE when BASIC authentication is expected.

2. Configure client to use BASIC explicitly (as mentioned in comment #0).

Comment 10 Kamil Dudka 2019-08-02 15:47:36 UTC
Per the upstream project issue noted in comment 5, we are currently unable to dynamically resolve the condition described. The recommendation for the time being is to set a specific authentication method via the /etc/yum.conf proxy_auth_method configuration option as described in the following article:

    The yum utility fails to connect to cdn.redhat.com when behind proxy - Red Hat Customer Portal
    https://access.redhat.com/solutions/4260571


At this time, this issue is being closed as WONTFIX. In the event that there are environmental factors in which the above configuration option does not resolve the condition, please reach out to Red Hat Support in order to gain further assistance.

    How to Engage Red Hat Support - Red Hat Customer Portal
    https://access.redhat.com/start/how-to-engage-red-hat-support