Bug 2095162 - after sssd update login with ipa accounts is broken
Summary: after sssd update login with ipa accounts is broken
Keywords:
Status: CLOSED DUPLICATE of bug 2095086
Alias: None
Product: Fedora
Classification: Fedora
Component: freeipa
Version: 36
Hardware: Unspecified
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: IPA Maintainers
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-06-09 07:45 UTC by rob.verduijn
Modified: 2022-06-09 11:46 UTC (History)
10 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-06-09 11:46:42 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker FREEIPA-8342 0 None None None 2022-06-09 07:54:29 UTC

Description rob.verduijn 2022-06-09 07:45:39 UTC
User-Agent:       Mozilla/5.0 (X11; Linux x86_64; rv:101.0) Gecko/20100101 Firefox/101.0
Build Identifier: 

Hello,

This moring I logged in to my desktop using my ipa account.
Updated my system and rebooted.
After this the login failed and I was forced to use a local account which still works.

Since I run fedora I cannot undo this update.

The logs show an unknown error.
krb5_child[14426]: Unknown code UUz 100
sudo[14257]: pam_sss(sudo-i:auth): authentication failure; logname=rob uid=xxx euid=0 tty=/dev/pts/8 ruser=rob rhost= user=rob
sudo[14257]: pam_sss(sudo-i:auth): received for user rob: 4 (System error)

I tested selinux to see if that was causing the problem by setting enforce 0
This did not help.

Time is in sync and logging in to the ipa server gui in firefox with an ipa account also works fine

anybody know how to get this working

rpm packages

Reproducible: Always

Steps to Reproduce:
1. update to latest patch level
2. reboot
3. try to login with ipa account
Actual Results:  
failed to login

Expected Results:  
succesfull login

Comment 1 rob.verduijn 2022-06-09 07:48:01 UTC
sssd package versions
python3-sssdconfig-2.7.1-1.fc36.noarch
sssd-2.7.1-1.fc36.x86_64
sssd-ad-2.7.1-1.fc36.x86_64
sssd-client-2.7.1-1.fc36.x86_64
sssd-common-2.7.1-1.fc36.x86_64
sssd-common-pac-2.7.1-1.fc36.x86_64
sssd-dbus-2.7.1-1.fc36.x86_64
sssd-idp-2.7.1-1.fc36.x86_64
sssd-ipa-2.7.1-1.fc36.x86_64
sssd-kcm-2.7.1-1.fc36.x86_64
sssd-krb5-2.7.1-1.fc36.x86_64
sssd-krb5-common-2.7.1-1.fc36.x86_64
sssd-ldap-2.7.1-1.fc36.x86_64
sssd-nfs-idmap-2.7.1-1.fc36.x86_64
sssd-proxy-2.7.1-1.fc36.x86_64
sssd-tools-2.7.1-1.fc36.x86_64

Comment 2 rob.verduijn 2022-06-09 09:15:07 UTC
Hi,

Just realized that undo might not work but downgrade does....so now I'm back at the 2.7.0 version of sssd
lowered the prio becuase it works again now

Rob

Comment 3 Rob Crittenden 2022-06-09 11:46:42 UTC

*** This bug has been marked as a duplicate of bug 2095086 ***


Note You need to log in before you can comment on or make changes to this bug.