Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
For bugs related to Red Hat Enterprise Linux 4 product line. The current stable release is 4.9. For Red Hat Enterprise Linux 6 and above, please visit Red Hat JIRA https://issues.redhat.com/secure/CreateIssue!default.jspa?pid=12332745 to report new issues.

Bug 246619

Summary: sshd needs to store forwarded gssapi creds before opening the pam session
Product: Red Hat Enterprise Linux 4 Reporter: Nalin Dahyabhai <nalin>
Component: opensshAssignee: Tomas Mraz <tmraz>
Status: CLOSED DUPLICATE QA Contact: Brian Brock <bbrock>
Severity: medium Docs Contact:
Priority: medium    
Version: 4.5CC: botsch
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-07-10 21:42:14 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 201265    

Description Nalin Dahyabhai 2007-07-03 13:47:46 UTC
This is more or less the same as bug #201341, and was originally upstream #918
(https://bugzilla.mindrot.org/show_bug.cgi?id=918).  Basically sshd doesn't
store forwarded GSSAPI credentials to disk before opening the PAM session for
the user, so modules don't have access to the credentials even when they may
have use for them.

Comment 2 Tomas Mraz 2007-07-10 21:42:14 UTC
Actually the patch I have to fix bug 216689 will solve this one as well.


*** This bug has been marked as a duplicate of 216689 ***

Comment 3 Nalin Dahyabhai 2007-07-11 13:31:34 UTC
You're right, it looks like it will.  Thanks!

Comment 4 Tomas Mraz 2007-07-23 11:10:45 UTC
Nalin, could you please test the latest openssh in dist-4E-qu-candidate whether
it fixes the problem?


Comment 5 Nalin Dahyabhai 2007-07-23 21:24:46 UTC
Seems to work properly in combination with the corresponding
dist-4E-qu-candidate pam_krb5 2.1.15-1 and later.  Thanks!

Comment 6 Dave Botsch 2007-09-14 04:42:40 UTC
Hi. What's the status and expected release of a fix for RHEL4 on this? The bug
this is marked as a duplicate of (bug 216689) is restricted, so the rest of the
community has no idea what's going on.

thanks!

Comment 7 Nalin Dahyabhai 2007-09-14 15:30:49 UTC
This should be fixed (well, #216689 is called out as fixed in the changelog) in
the openssh packages in the beta channel.