Bug 684458 - Review QMF plugin defaults for secure broker auth
Summary: Review QMF plugin defaults for secure broker auth
Keywords:
Status: CLOSED DUPLICATE of bug 687872
Alias: None
Product: Red Hat Enterprise MRG
Classification: Red Hat
Component: condor-qmf
Version: Development
Hardware: All
OS: All
high
high
Target Milestone: 2.0
: ---
Assignee: Robert Rati
QA Contact: MRG Quality Engineering
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-03-12 18:31 UTC by Pete MacKinnon
Modified: 2011-03-17 14:41 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-03-17 14:41:47 UTC
Target Upstream Version:


Attachments (Terms of Use)

Description Pete MacKinnon 2011-03-12 18:31:07 UTC
Changes introduced in BZ 606391 have impacted the default OOTB SASL-based authorization for the condor qmf plugins. In the absence of the new configuration described in 606391, the plugins won't be able to connect to establish an authenticated connection to the broker when it has SASL turned on. Note that the schedd plugin relies on broker SASL auth in order to provide us with a userid string that is checked in the mgmt plugin. This is our only security safeguard for submissions from QMF at this time.

Some options:
1) revert defaults in plugins, etc. to use "guest/guest" identity when initializing the agent if it can't get condor params for same. The guest user is OOTB with the broker install IIRC.
2) doc updates that explicitly expand the broker auth setup instructions for secured submissions
 - broker & sasl config AND
 - condor user/password config from 606391

Comment 1 Pete MacKinnon 2011-03-15 15:30:53 UTC
Looks like option #2 is really what is called for. We can no longer rely on the guest user id being an OOTB credential. The ACL file passed to the broker like this: 

sudo qpidd --load-module /usr/lib/qpid/daemon/acl.so --acl-file /full/path/to/qpidd.acl --auth=yes

should have lines like:

acl allow cumin@QPID all all
acl allow anonymous@QPID all all
acl deny all all

Comment 2 Robert Rati 2011-03-17 14:41:47 UTC
This is really a documentation issue.

*** This bug has been marked as a duplicate of bug 687872 ***


Note You need to log in before you can comment on or make changes to this bug.