Bug 591681 - RFE: Gray out KDC and admin fields when kerberos parameters are discovered via DNS
Summary: RFE: Gray out KDC and admin fields when kerberos parameters are discovered vi...
Alias: None
Product: Fedora
Classification: Fedora
Component: authconfig
Version: 13
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Tomas Mraz
QA Contact: Fedora Extras Quality Assurance
Keywords: FutureFeature
Depends On:
Blocks: 591716
TreeView+ depends on / blocked
Reported: 2010-05-12 20:09 UTC by Stjepan Gros
Modified: 2010-08-10 14:18 UTC (History)
3 users (show)

Clone Of:
: 591716 (view as bug list)
Last Closed: 2010-08-10 14:18:35 UTC

Attachments (Terms of Use)

Description Stjepan Gros 2010-05-12 20:09:40 UTC
Description of problem:

After selecting FreeIPA as authentication server in authconfig and marking checkbox 'Use DNS to locate KDC for realms' it would be good that the fields KDCs and 'Admin servers' are grayed out?

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. Just configure FreeIPA authentication with DNS used to locate KDCs.

Additional info:
In /etc/krb5.conf DNS resolution is selected and in the sam time values of KDC and admin server are filled with exact values. The question is which values have higher priority?

Comment 1 Tomas Mraz 2010-05-12 20:30:39 UTC
According to the krb5.conf manpage the DNS is used only when the realm and KDC is not filled in. I am not sure whether sssd behaves the same.

Comment 2 Stephen Gallagher 2010-05-12 20:52:27 UTC
Jakub, can you clarify? I think our default behavior is the same, but you're the authority.

Comment 3 Jakub Hrozek 2010-05-13 09:52:37 UTC
Yes, even though we don't have any equivalent of dns_lookup_kdc (which is the krb5.conf option set by the 'Use DNS to locate KDC for realms' checkbox), we always use service discovery when no KDCs are set.

We don't have any equivalent of 'dns_lookup_realm' in SSSD at all - which is the second check box "Use DNS to resolve hosts to realms".

Comment 4 Stjepan Gros 2010-05-13 10:05:42 UTC
Kerberos realm is also retrieved from DNS, so it also should be either grayed out or maybe automatically filled in.

Note You need to log in before you can comment on or make changes to this bug.