Bug 833024 - [RFE] Teach GSSD to use DIR:/run/user/$UID for Kerberos DIR caches
[RFE] Teach GSSD to use DIR:/run/user/$UID for Kerberos DIR caches
Status: CLOSED ERRATA
Product: Fedora
Classification: Fedora
Component: nfs-utils (Show other bugs)
rawhide
All Linux
unspecified Severity high
: ---
: ---
Assigned To: Steve Dickson
Fedora Extras Quality Assurance
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2012-06-18 08:07 EDT by Stephen Gallagher
Modified: 2012-09-17 18:33 EDT (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2012-09-17 18:33:22 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)
proposed changes for recognizing "DIR" cache types (4.85 KB, patch)
2012-08-16 14:07 EDT, Nalin Dahyabhai
no flags Details | Diff
proposed changes for parameterizing the search path with %U for IDs (3.89 KB, patch)
2012-08-16 14:09 EDT, Nalin Dahyabhai
no flags Details | Diff

  None (edit)
Description Stephen Gallagher 2012-06-18 08:07:11 EDT
Description of problem:
As part of the Fedora 18 Feature https://fedoraproject.org/wiki/Features/KRB5DirCache, GSSD needs to be taught about the new standard location for credential caches.

Beginning with Fedora 18, we will now be storing credential caches in the new DIR format added in MIT Kerberos 1.10. This allows us to store multiple TGTs for different realms simultaneously. Additionally, Fedora has adopted a new standard location of /run/user/UID/ccdir for this storage. This will reduce the need for trolling /tmp for credential caches owned by the user, as it can be assumed that for most situations, the cache location will be well-known[1].

Version-Release number of selected component (if applicable):
nfs-utils-1.2.6-5.fc18

How reproducible:
N/A

Expected results:
GSSD and any other necessary NFS utilities will attempt to use DIR:/run/user/UID/ccdir as the default cache location. (Substituting UID for the actual numeric value, of course).


Additional info:

[1] It is possible for this default location to be changed by an administrator, but we make the assumption that if they do so, they know what they are doing and will deal with other issues that arise from it.
Comment 1 Stephen Gallagher 2012-06-18 10:27:38 EDT
For the record, this can be tested by using sssd-1.9.0-6.fc18.beta2 or later for krb5 login. That will put the credential cache in the proper place by default.
Comment 2 Stephen Gallagher 2012-08-07 15:20:54 EDT
From an IRC conversation today:


(02:30:26 PM) sgallagh: steved: At the start of gssd_setup_krb5_user_gss_ccache(), check whether the file /run/user/UID/ccdir/primary exists
(02:31:39 PM) sgallagh: Return the dirent for the parent directory (/run/user/UID/ccdir). In gssd_setup_krb5_user_gss_ccache() check whether the path returned from gssd_find_existing_krb5_ccache() is a file or directory. If it's a directory, do the snprintf() with DIR: instead of FILE:
(02:31:52 PM) sgallagh: steved: I *think* that's all you will need to do for this to work.
(02:32:38 PM) sgallagh: The reason to check for /run/user/UID/ccdir/primary is that all DIR: cache directories must contain a file with this name (it tells libkrb5 where to look).
(02:32:54 PM) sgallagh: So that will be enough confirmation that there is a DIR: cache here for gssd to use it.
Comment 3 Nalin Dahyabhai 2012-08-14 19:35:15 EDT
After more discussion, the recommended order is now:
* directories under /run/user/$UID matching the pattern "krb5cc*"
  No "_" is expected because the UID is already a separate component in the pathname, and the "_" was typically there to visually separate the UID from the rest of the filename.
* files under /run/user/$UID matching the pattern "krb5cc*"
  Same reason as above for not including the "_" in the matching pattern.
* files under /tmp matching the pattern "krb5cc*"
  The current default matching prefix ("krb5cc_*") would still work here just as well, but changing it could make the implementation simpler.
Comment 4 Nalin Dahyabhai 2012-08-16 14:07:16 EDT
Created attachment 604985 [details]
proposed changes for recognizing "DIR" cache types
Comment 5 Nalin Dahyabhai 2012-08-16 14:09:00 EDT
Created attachment 604986 [details]
proposed changes for parameterizing the search path with %U for IDs
Comment 6 Steve Dickson 2012-08-20 09:28:44 EDT
Nalin,

Would you mind posting these patches to upstream at linux-nfs@vger.kernel.org,

tia...
Comment 7 Nalin Dahyabhai 2012-08-20 12:10:14 EDT
Steve, some of the context in these two depends on other patches that are already applied in the package.  What's the baseline that versions pitched upstream should be using?  Just as important (to me, anyway), do they look correct to you?
Comment 8 Steve Dickson 2012-08-20 13:48:15 EDT
(In reply to comment #7)
> Steve, some of the context in these two depends on other patches that are
> already applied in the package.  What's the baseline that versions pitched
> upstream should be using?
The upstream tree is at git://linux-nfs.org/~steved/nfs-utils

> Just as important (to me, anyway), do they look
> correct to you?
I took a quick look at them and they look reasonable. I have not done any
testing yet, but as long as gssd can fall back to look in legacy places
for the cache, I think we are good...
Comment 9 Nalin Dahyabhai 2012-08-21 16:53:31 EDT
Submitted, though I probably should have elaborated more in the patch comments.
Comment 10 Fedora Update System 2012-08-23 14:44:04 EDT
nfs-utils-1.2.6-12.fc18 has been submitted as an update for Fedora 18.
https://admin.fedoraproject.org/updates/nfs-utils-1.2.6-12.fc18
Comment 11 Fedora Update System 2012-08-23 21:23:57 EDT
Package nfs-utils-1.2.6-12.fc18:
* should fix your issue,
* was pushed to the Fedora 18 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing nfs-utils-1.2.6-12.fc18'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2012-12618/nfs-utils-1.2.6-12.fc18
then log in and leave karma (feedback).
Comment 12 Fedora Update System 2012-09-17 18:33:22 EDT
nfs-utils-1.2.6-12.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.