Bug 2217895 - GPO setting should be part of AD setup
Summary: GPO setting should be part of AD setup
Keywords:
Status: ASSIGNED
Alias: None
Product: Red Hat Satellite
Classification: Red Hat
Component: Authentication
Version: 6.14.0
Hardware: Unspecified
OS: Unspecified
unspecified
medium
Target Milestone: Unspecified
Assignee: Adam Lazik
QA Contact: Satellite QE Team
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-06-27 12:14 UTC by Lukáš Hellebrandt
Modified: 2023-08-09 11:46 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker SAT-18657 0 None None None 2023-06-27 12:16:03 UTC

Description Lukáš Hellebrandt 2023-06-27 12:14:28 UTC
Document URL: 
https://access.redhat.com/documentation/en-us/red_hat_satellite/6.13/html/installing_satellite_server_in_a_connected_network_environment/configuring_external_authentication_satellite#Kerberos_Configuration_in_Web_Browsers_satellite

Section Number and Name: 
5.3.4. Kerberos Configuration in Web Browsers

Describe the issue:
There is a note about GPO-PAM mapping.
I think this shouldn't be a note.
I think this should be in the section 5.3.3. Configuring Direct AD Integration with GSS-Proxy.
Because this setting is required (I wasn't able to get AD auth working without it) and it needs to be done on the Satellite, not on the client (running the web browser).

Related:
https://bugzilla.redhat.com/show_bug.cgi?id=2117523 but it was closed because there is already this KBA: https://access.redhat.com/solutions/6982443 ... however, 1) KBA isn't a proper documentation and 2) this is actually in docs but in a wrong place and incorrectly marked.

Comment 1 Lukáš Hellebrandt 2023-06-27 12:16:52 UTC
Missing that causes this error on login in WebUI or with ticket:

PAM authentication failed for user foobar: User not known to the underlying authentication module, referer: <FQDN>

Comment 3 Adam Lazik 2023-07-25 14:33:33 UTC
Hello!
Currently in progress of making the PR with requested changes.
Link to draft PR here: https://github.com/theforeman/foreman-documentation/pull/2307


Note You need to log in before you can comment on or make changes to this bug.