Bug 239223 - krb5 should not use host/* principals
krb5 should not use host/* principals
Status: CLOSED UPSTREAM
Product: Fedora
Classification: Fedora
Component: koji (Show other bugs)
6
All Linux
medium Severity medium
: ---
: ---
Assigned To: David Cantrell
Fedora Extras Quality Assurance
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2007-05-06 08:41 EDT by Enrico Scholz
Modified: 2013-01-09 20:37 EST (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2007-11-15 11:46:17 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Enrico Scholz 2007-05-06 08:41:00 EDT
Description of problem:

There is an hardcoded server principal of 'host/%s' in
ClientSession::_serverPrincipal() in
/usr/lib/python2.4/site-packages/koji/__init__.py


This is bad because 'host/*' principals are for system services only and the
keytab can/must not be read by non-root users. As koji services (hub) are run by
the 'httpd' user, this will not work.

There should be used (customizable) principal names like HTTP/* instead of.



Version-Release number of selected component (if applicable):

koji-1.1-1
Comment 1 Jesse Keating 2007-06-12 15:54:34 EDT
Filed upstream as https://hosted.fedoraproject.org/projects/koji/ticket/32 
Waiting for an upstream fix to release.
Comment 2 Jesse Keating 2007-11-15 11:46:17 EST
Closing this as upstream here to.  Really needs to be fixed upstream and it will
filter down to the Fedora release.

Note You need to log in before you can comment on or make changes to this bug.