Red Hat Bugzilla – Bug 679082
SSSD IPA provider should honor the krb5_realm option
Last modified: 2015-01-04 18:46:36 EST
Description of problem: The kerberos domain is assumed to be the upper-case realm.
Notes for QA: this bug is to ensure that if the krb5_realm is manually set for an 'id_provider = ipa' or 'auth_provider = ipa' domain, that the krb5_realm is used for all kerberos-related activities.
This is relevant if ipa-client-install is run with the --realm command. We need to ensure that when krb5_realm is set in sssd.conf, it is honored everywhere.
Verified using: sssd-1.5.5-0.20110405T0615z.el6.x86_64 installed ipa server as - ipa-server-install --setup-dns --forwarder=10.14.63.12 -p Secret123 -P Secret123 -a Secret123 -r QWQW and verified sssd.conf, and default.conf have the right entries: sssd.conf: section for [domain/testrelm] includes: krb5_realm = QWQW ipa_domain = testrelm section for [domain/default] includes: krb5_realm = QWQW default.conf includes: basedn=dc=qwqw realm=QWQW domain=testrelm xmlrpc_uri=https://rhel61-server5.testrelm/ipa/xml ldap_uri=ldapi://%2fvar%2frun%2fslapd-QWQW.socket also verified kinit # kinit admin Password for admin@QWQW:
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on therefore solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2011-0560.html