Bug 743507 - [RFE] Improve SASL authentication method negotiation
Summary: [RFE] Improve SASL authentication method negotiation
Keywords:
Status: CLOSED UPSTREAM
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: sssd
Version: 7.0
Hardware: All
OS: Linux
unspecified
low
Target Milestone: rc
: 7.1
Assignee: SSSD Maintainers
QA Contact: Namita Soman
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-10-05 07:37 UTC by Ondrej Valousek
Modified: 2020-05-02 16:27 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: Enhancement
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-11-23 13:11:05 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github SSSD sssd issues 2072 0 None None None 2020-05-02 16:27:04 UTC

Description Ondrej Valousek 2011-10-05 07:37:44 UTC
SASL authentication method is currently detected automatically the way that first method which is supported by both ldap server and client (sssd) is used.

However this might fail in some circumstances - example when communicating with Active Directory controllers. In this case there are three common SASL methods supported by both parties - SASL/EXTERNAL, SASL/GSSAPI and SASL/MD5 - so SASL/EXTERNAL is always used (being the first) - but it will almost certainly fail. It would be nice to attempt to connect via the rest of auth methods if the first one fails.

Note the workaround is simple as we can force the auth method via the 'ldap_sasl_mech' parameter - so please take this as suggestion only - does not have to be implemented at all.

Comment 3 Stephen Gallagher 2011-10-05 11:54:12 UTC
Upstream ticket:
https://fedorahosted.org/sssd/ticket/1030

Comment 4 Dmitri Pal 2011-10-05 13:21:08 UTC
Why would SASL/EXTERNAL fail? Is it because it is not configured? Because cert is missing? 

Is there a default method that would work with high probability? And if so should it be added to the default set of config arguments covered in #743505 as yet another implied setting?

Comment 5 Ondrej Valousek 2011-10-05 13:32:29 UTC
To be honest, I do not know (I have no idea how EXTERNAL works) - I just wanted to express that I would have perhaps expected, that it would eventually try GSSAPI which would succeed then.

That's also said that yes in #743505 this should be also the implied setting..
Ondrej

Comment 8 Jakub Hrozek 2014-07-02 13:06:01 UTC
Upstream ticket is targeting 1.13, reproposing for 7.2

Comment 9 Jakub Hrozek 2016-11-23 13:11:05 UTC
Since this problem is already tracked in an upstream ticket and this bugzilla is not being planned for any immediate release either in RHEL or upstream, I'm closing this bugzilla with the resolution UPSTREAM.

Please reopen this bugzilla report if you disagree.


Note You need to log in before you can comment on or make changes to this bug.