Hide Forgot
Description of problem: FreeIPA v2 was originally going to support time rules in the HBAC rules. However, this was dropped from the final version. However, SSSD in RHEL 6.0 expects these rules to be present and will cause unexpected denials if they are not. We need to remove these rules. Version-Release number of selected component (if applicable): sssd-1.2.1-28.el6_0.4 How reproducible: Every time Steps to Reproduce: 1. Configure SSSD to use IPA as a back-end 2. Attempt to log in as any user. Actual results: User is denied because nonexistent time-rules is interpreted as "never allow" Expected results: The lack of time rules should be disregarded. Additional info:
Proposing for Z-stream so that 6.0 clients will not have issues connecting to FreeIPA servers.
Default rule verified: Server: ipa-server-2.0.0-13.el6.x86_64 Client: ipa-client-2.0.0-13.el6.x86_64 User added and successfully SSO SSH to client machine after getting credentials We apply HBAC rules and test also.
[root@ipaqavmh ~]# ipa hbacrule-show testdenyssh Rule name: testdenyssh Rule type: deny Source host category: all Description: test deny Enabled: TRUE Users: mmouse Hosts: ipaqavmh.rhts.eng.bos.redhat.com Services: sshd Mar 1 10:04:21 ipaqavmh sshd[13984]: pam_sss(sshd:auth): authentication success; logname= uid=0 euid=0 tty=ssh ruser= rhost=hp-dl180g6-01.rhts.eng.bos.redhat.com user=mmouse Mar 1 10:04:21 ipaqavmh sshd[13984]: pam_sss(sshd:account): Access denied for user mmouse: 6 (Permission denied
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on therefore solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2011-0560.html