Bug 2127822
| Summary: | Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Branimir <branimir.pranjic> | ||||||||||||
| Component: | sssd | Assignee: | Sumit Bose <sbose> | ||||||||||||
| Status: | CLOSED ERRATA | QA Contact: | Steeve Goveas <sgoveas> | ||||||||||||
| Severity: | high | Docs Contact: | |||||||||||||
| Priority: | unspecified | ||||||||||||||
| Version: | 8.7 | CC: | abokovoy, aboscatt, abroy, atikhono, pbrezina, rcritten, sbose, tscherf | ||||||||||||
| Target Milestone: | rc | Keywords: | Triaged, ZStream | ||||||||||||
| Target Release: | --- | Flags: | pm-rhel:
mirror+
|
||||||||||||
| Hardware: | x86_64 | ||||||||||||||
| OS: | Linux | ||||||||||||||
| Whiteboard: | sync-to-jira | ||||||||||||||
| Fixed In Version: | sssd-2.8.1-1.el8 | Doc Type: | If docs needed, set a value | ||||||||||||
| Doc Text: | Story Points: | --- | |||||||||||||
| Clone Of: | |||||||||||||||
| : | 2128544 (view as bug list) | Environment: | |||||||||||||
| Last Closed: | 2023-05-16 09:07:56 UTC | Type: | --- | ||||||||||||
| Regression: | --- | Mount Type: | --- | ||||||||||||
| Documentation: | --- | CRM: | |||||||||||||
| Verified Versions: | Category: | --- | |||||||||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||||||||
| Embargoed: | |||||||||||||||
| Bug Depends On: | |||||||||||||||
| Bug Blocks: | 2128544 | ||||||||||||||
| Attachments: |
|
||||||||||||||
|
Description
Branimir
2022-09-19 07:03:14 UTC
Created attachment 1912856 [details]
Configuration file krb5.conf
Created attachment 1912857 [details]
Configuration file sssd.conf
Created attachment 1912858 [details]
Log file krb5_child.log when debug_level is set to 9
Created attachment 1912859 [details]
Log file krb5_child.log without debug_level
Created attachment 1912860 [details]
Log file secure.log
This needs to be analyzed by SSSD team. Hi,
Centos Stream 8 is using the upcoming version of SSSD with additional checks on the PAC enabled. For this a Kerberos service ticket for an entry from the keytab must be requested from the KDC. This is the same operation as done during Kerberos ticket validation which is enabled by default for id_provider=ipa but is explicitly disabled in your sssd.conf by 'krb5_validate = False'. I assume there where issues in the past with ticket validation which now triggers the error while trying to check the PAC.
To cut it short a workaround should be to add
pac_check = no_check
to the [pac] section of sssd.conf and to restart SSSD.
Alexander, I can see two ways to make this more user-friendly. Currently we try to request the service ticket if any PAC validation option except 'no_check' is set. But since there is a dedicated option 'pac_present' to required a PAC we can only force-fully request the ticket in this case and can respect the setting of `krb5_validate` in the other cases. Or we always follow `krb5_validate` even if `pac_present` is set. In both cases there should of course be a message in the logs explaining why one or the other option is ignored/overwritten. Which one would you prefer or keep it as it is?
bye,
Sumit
I think following krb5_validate even if pac_present is set would be more friendly to older setups. Yes, adding a message in the logs that we'd recommend and prefer pac_check setting would be good. Upstream PR: https://github.com/SSSD/sssd/pull/6356 @Sumit @Thorsten do we think we should write an insight rule which will check cus system if they are using krb5_validate = false. In this way at least we can generate a warning to cus who are using insights. (In reply to Abhijit Roy from comment #20) > @Sumit @Thorsten do we think we should write an insight rule which will > check cus system if they are using krb5_validate = false. In this way at > least we can generate a warning to cus who are using insights. Hi, having an Insight rule is not a bad idea but please note although not recommended admins might set 'krb5_validate = false' even if ticket validation would work to speed up authentication. In this case the warning would be a false positive since authentication would work after the update as well. So I think it all depends on the message Insights will display to the admin in this case. bye, Sumit Pushed PR: https://github.com/SSSD/sssd/pull/6356 * `master` * f4dffaeaef16f146fc03970f62761fc335a3c7cc - krb5: respect krb5_validate for PAC checks * `sssd-2-7` * 72132c413a2b19fbc21120ce51698978fd926360 - krb5: respect krb5_validate for PAC checks (In reply to Sumit Bose from comment #21) > (In reply to Abhijit Roy from comment #20) > > @Sumit @Thorsten do we think we should write an insight rule which will > > check cus system if they are using krb5_validate = false. In this way at > > least we can generate a warning to cus who are using insights. > > Hi, > > having an Insight rule is not a bad idea but please note although not > recommended admins might set 'krb5_validate = false' even if ticket > validation would work to speed up authentication. In this case the warning > would be a false positive since authentication would work after the update > as well. So I think it all depends on the message Insights will display to > the admin in this case. > > bye, > Sumit Hi Sumit, I can try writing an insight rule could you please suggest what msg would be better. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (sssd bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2023:2986 |