Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 2017402

Summary: Adding several allowed SASL mechanisms does not behave correctly
Product: Red Hat Directory Server Reporter: sgouvern
Component: cockpit-389-dsAssignee: mreynolds
Status: CLOSED ERRATA QA Contact: RHDS QE <ds-qe-bugs>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 12.0CC: ldap-maint, mreynolds
Target Milestone: ---   
Target Release: dirsrv-12.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: redhat-ds-12-9000020211123032220.032d475b Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2022-05-18 15:28:06 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description sgouvern 2021-10-26 12:55:08 UTC
Description of problem:
Adding several allowed SASL mechanisms, and saving settings, makes all the added mechanisms been merged in a single item. No mean to separate them and remove a single one.
Then only the previously selected SASL mechanisms appear in the list of allowed SASL mechanisms, so you cannot choose to add one from the default list.
And you can add again one proposed, that has already been added previously.


Version-Release number of selected component (if applicable):
cockpit-389-ds-2.0.10-1

How reproducible:
always

Steps to Reproduce:
1.Open the WebUI console, create an instance
2.Go to 'Server Settings' / 'SASL settings and mappings'
3.'Allowed SASL Mechanisms': extend the list choose several mechanisms in the list
4. click 'save settings' 

Actual results:
the previously selected mechanisms appear in a single item. No mean to separate them and for example remove only one of them.
Extending the list again shows only the previously selected mechanisms.
You can select again one of them. 
Then when clicking 'save settings' a message is displayed : "Successfully updated SASL configuration. These changes require the server to be restarted to take effect."
But the added mechanism has been removed from the displayed list (but is present in dse.ldif)
It results in dse.ldif showing several times the same mechanism :
nsslapd-allowed-sasl-mechanisms: EXTERNAL GSSAPI DIGEST-MD5 EXTERNAL GSSAPI DI
 GEST-MD5

Expected results:
selected mechanisms appear as separate items.
Extending the list again shows all initially available mechanisms.
Entering the same mechanism several times is rejected 

Additional info:

It seems that dsconf is unable to get the nsslapd-allowed-sasl-mechanism :
# dsconf inst1 -D "cn=directory manager" -w secret12 config get nsslapd-allowed-sasl-mechanism

Nothing is returned

Comment 3 sgouvern 2022-02-01 13:54:25 UTC
With cockpit-389-ds-2.0.12-2.scrmod+el9dsrv+13724+3613bd96.noarch 

Following the steps described in https://bugzilla.redhat.com/show_bug.cgi?id=2017402#c0, adding allowed SASL mechanisms is processed correctly.

Marking as verified

Comment 5 errata-xmlrpc 2022-05-18 15:28:06 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (redhat-ds:12 bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2022:4664