Bug 688158 - [gdm] Login using LDAP authentication isn't handled well in gdm-binary
Summary: [gdm] Login using LDAP authentication isn't handled well in gdm-binary
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: gdm
Version: 6.1
Hardware: All
OS: Linux
unspecified
urgent
Target Milestone: rc
: ---
Assignee: Ray Strode [halfline]
QA Contact: Desktop QE
URL:
Whiteboard:
Depends On:
Blocks: 661713
TreeView+ depends on / blocked
 
Reported: 2011-03-16 13:52 UTC by Jakub Libosvar
Modified: 2011-12-06 17:57 UTC (History)
4 users (show)

Fixed In Version: gdm-2.30.4-24.el6
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-12-06 17:57:58 UTC
Target Upstream Version:


Attachments (Terms of Use)
Messages and secure logs (115.82 KB, application/x-gzip)
2011-03-16 13:52 UTC, Jakub Libosvar
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2011:1721 0 normal SHIPPED_LIVE gdm bug fix update 2011-12-06 01:02:11 UTC

Description Jakub Libosvar 2011-03-16 13:52:29 UTC
Created attachment 485737 [details]
Messages and secure logs

Description of problem:
When using UPN or domain\uname on logging to machine, parameter passed to id doesn't escape backslash which leads to failure obtaining uid (passed is 'id -u domain\name' instead of 'id -u domain\\name'

Version-Release number of selected component (if applicable):
gdm-2.30.4-21

How reproducible:
Always

Steps to Reproduce:
1. Have LDAP authentication
2. Try to login with user from LDAP
  
Actual results:
Password is authenticated successfully but when gdm-binary is obtaining user's id, it fails and user gets back to login screen

Expected results:
User is logged in successfully

Additional info:
messages, secure log attached

Mar 16 14:34:47 r6-x86-d gdm-binary[1740]: WARNING: Command 'id -u RHEV\vdcadmin' exited unsuccessfully with code: 1

[root@r6-x86-d log]# id -u rhev\vdcadmin
id: rhevvdcadmin: No such user
[root@r6-x86-d log]# id -u rhev\\vdcadmin
16777216

Comment 2 RHEL Program Management 2011-03-16 14:08:12 UTC
This request was evaluated by Red Hat Product Management for
inclusion in the current release of Red Hat Enterprise Linux.
Because the affected component is not scheduled to be updated
in the current release, Red Hat is unfortunately unable to
address this request at this time. Red Hat invites you to
ask your support representative to propose this request, if
appropriate and relevant, in the next release of Red Hat
Enterprise Linux. If you would like it considered as an
exception in the current release, please ask your support
representative.

Comment 3 Ray Strode [halfline] 2011-05-04 15:28:25 UTC
ah, this is probably a side effect of the workaround mentioned by bug 621700
the patch has:

command_line = g_strdup_printf ("id -u %s", username);

and it should probably have

command_line = g_strdup_printf ("id -u '%s'", username);


(and likewise for group)

Comment 4 RHEL Program Management 2011-05-23 15:19:30 UTC
This request was evaluated by Red Hat Product Management for inclusion
in a Red Hat Enterprise Linux maintenance release. Product Management has 
requested further review of this request by Red Hat Engineering, for potential
inclusion in a Red Hat Enterprise Linux Update release for currently deployed 
products. This request is not yet committed for inclusion in an Update release.

Comment 6 Ray Strode [halfline] 2011-07-27 20:33:39 UTC
a fix for this is building now

Comment 9 errata-xmlrpc 2011-12-06 17:57:58 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2011-1721.html


Note You need to log in before you can comment on or make changes to this bug.