Bug 1854557 - [RFE] ipa-client-install forces nsupdate to bind with gssapi
Summary: [RFE] ipa-client-install forces nsupdate to bind with gssapi
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 8
Classification: Red Hat
Component: ipa
Version: 8.3
Hardware: All
OS: All
medium
medium
Target Milestone: beta
: 8.4
Assignee: Thomas Woerner
QA Contact: ipa-qe
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-07-07 16:37 UTC by Striker Leggette
Modified: 2021-11-09 23:03 UTC (History)
11 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-11-09 18:21:53 UTC
Type: Bug
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker FREEIPA-7168 0 None None None 2021-10-25 18:22:33 UTC
Red Hat Issue Tracker RHELPLAN-48824 0 None None None 2021-10-25 18:22:32 UTC
Red Hat Product Errata RHBA-2021:4230 0 None None None 2021-11-09 18:22:11 UTC

Description Striker Leggette 2020-07-07 16:37:32 UTC
[+] Description of problem:
 - During the ipa-client-install, nsupdate runs but tries to bind with GSSAPI. If the bind fails, nsupdate stops.

[+] How reproducible:
 - Always

[+] Steps to Reproduce:
 1. Run ipa-client-install.

[+] Expected results:
 - nsupdate tries to bind with gssapi but then tries unsecure if gssapi fails

Comment 2 Alexander Bokovoy 2020-07-08 05:08:40 UTC
This is by design. GSS-TSIG is the only way we can securely authenticate to the authorative DNS server at this point, we have no knowledge or means to do otherwise.

There are two places where a client might do nsupdate in FreeIPA domain:
 - during enrollment process, in ipa-client-install
 - during IP address changes in SSSD

SSSD has 'dyndns_auth' option that can be used to force insecure updates with 'none' value.

If we want to have any flexibility here, we probably need to retry nsupdate without GSS-TSIG if tsig version failed and then if that succeeded, set 'dyndns_auth = none' in SSSD configuration.

Comment 5 François Cami 2020-07-09 10:30:51 UTC
Upstream ticket:
https://pagure.io/freeipa/issue/8402

Comment 9 François Cami 2021-06-29 08:39:38 UTC
master:
72f44b5 ipa-client-install: remove fsync in do_nsupdate()
20c7bd5 ipa-client-install: invoke nsupdate twice (GSS-TSIG, plain)
2e31e84 ipa-client-install: update sssd.conf if nsupdate requires -g

ipa-4-9:
e82f253 ipa-client-install: remove fsync in do_nsupdate()
a8588c5 ipa-client-install: invoke nsupdate twice (GSS-TSIG, plain)
3cbd24d ipa-client-install: update sssd.conf if nsupdate requires -g

Comment 18 Rob Crittenden 2021-08-12 20:37:58 UTC
Automated test
Fixed upstream
master:
https://pagure.io/freeipa/c/dabf2763f8be750596f9f6e998bce985793e89a8

Comment 19 Florence Blanc-Renaud 2021-08-13 06:15:32 UTC
Automated test
Fixed upstream
ipa-4-9:
https://pagure.io/freeipa/c/4fdab0c94c4e17e42e5f38a0e671bea39bcc9b74

Comment 21 anuja 2021-08-16 12:06:28 UTC
Verified using:

1: runner.log
2021-08-16T08:44:03 ok: [master.ipa.test] => (item=ipa-server) => 
2021-08-16T08:44:03   msg:
2021-08-16T08:44:03   - arch: x86_64
2021-08-16T08:44:03     epoch: null
2021-08-16T08:44:03     name: ipa-server
2021-08-16T08:44:03     release: 4.module+el8.5.0+11912+1b4496cf
2021-08-16T08:44:03     source: rpm
2021-08-16T08:44:03     version: 4.9.6


2: test_result.txt

2021-08-16T08:46:33 ============================= test session starts ==============================
2021-08-16T08:46:33 platform linux -- Python 3.6.8, pytest-3.10.1, py-1.10.0, pluggy-0.13.1 -- /usr/bin/python3
2021-08-16T08:46:33 cachedir: .pytest_cache
2021-08-16T08:46:33 metadata: {'Python': '3.6.8', 'Platform': 'Linux-4.18.0-330.el8.x86_64-x86_64-with-redhat-8.5-Ootpa', 'Packages': {'pytest': '3.10.1', 'py': '1.10.0', 'pluggy': '0.13.1'}, 'Plugins': {'metadata': '1.11.0', 'html': '1.22.1', 'multihost': '3.0', 'sourceorder': '0.5'}}
2021-08-16T08:46:33 rootdir: /tmp/wp/freeipa, inifile: tox.ini
2021-08-16T08:46:33 plugins: metadata-1.11.0, html-1.22.1, multihost-3.0, sourceorder-0.5
2021-08-16T08:46:33 collecting ... collected 1 item
2021-08-16T08:46:33 
2021-08-16T08:53:06 ipatests/test_integration/test_installation_client.py::TestClientInstallBind::test_client_nsupdate PASSED [100%]
2021-08-16T08:53:06 
2021-08-16T08:53:06 ------------------ generated xml file: /tmp/wp/twd/junit.xml -------------------
2021-08-16T08:53:06 ------------- generated html file: file:///tmp/wp/twd/report.html --------------
2021-08-16T08:53:06 ========================== 1 passed in 392.13 seconds ==========================

Comment 23 errata-xmlrpc 2021-11-09 18:21:53 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (ipa bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2021:4230


Note You need to log in before you can comment on or make changes to this bug.