Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1868597

Summary: mod_auth_openidc package missing on upgrade
Product: [oVirt] ovirt-appliance Reporter: Yedidyah Bar David <didi>
Component: GeneralAssignee: Yedidyah Bar David <didi>
Status: CLOSED CURRENTRELEASE QA Contact: Pavol Brilla <pbrilla>
Severity: medium Docs Contact:
Priority: medium    
Version: ---CC: bugs
Target Milestone: ovirt-4.4.3Flags: pm-rhel: ovirt-4.4+
pm-rhel: planning_ack+
sbonazzo: devel_ack+
lleistne: testing_ack+
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: ovirt-engine-appliance-4.4-20201025165032.1.el8 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
: 1874867 (view as bug list) Environment:
Last Closed: 2020-10-26 08:01:35 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: Integration RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1874867    

Description Yedidyah Bar David 2020-08-13 08:45:37 UTC
Description of problem:

Didn't verify this myself, but I think that people following [1] will fail upgrading to 4.4 (or restoring on 4.3) if the package mod_auth_openidc is missing. So we should consider including it in the appliance.

This might not be enough for making restore/upgrade succeed - we should probably also backup and restore various configuration files etc.

If this bug prevents SSO login, but does not prevent "normal" login (e.g. with admin@internal), it's less critical, and can be handled manually by users after the restore/upgrade (by installing the package and reconfiguring stuff based on [1]). I didn't test this, so not sure. I am pretty certain that if we (or users) patch/hook-into engine-backup to also backup/restore the httpd conf file that uses this module, it will make httpd start to fail, thus engine-setup to fail.

[1] https://blogs.ovirt.org/2019/01/federate-ovirt-engine-authentication-to-openid-connect-infrastructure/

Comment 2 Sandro Bonazzola 2020-11-11 06:45:38 UTC
This bugzilla is included in oVirt 4.4.3 release, published on November 10th 2020.

Since the problem described in this bug report should be resolved in oVirt 4.4.3 release, it has been closed with a resolution of CURRENT RELEASE.

If the solution does not work for you, please open a new bug report.