Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 854997 - Add details about TGT validation to sssd-krb5 man page
Add details about TGT validation to sssd-krb5 man page
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: sssd (Show other bugs)
6.4
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: Jakub Hrozek
Kaushik Banerjee
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2012-09-06 09:34 EDT by Dmitri Pal
Modified: 2013-02-21 04:36 EST (History)
3 users (show)

See Also:
Fixed In Version: sssd-1.9.2-1.el6
Doc Type: Bug Fix
Doc Text:
No Documentation Needed
Story Points: ---
Clone Of:
Environment:
Last Closed: 2013-02-21 04:36:58 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2013:0508 normal SHIPPED_LIVE Low: sssd security, bug fix and enhancement update 2013-02-20 16:30:10 EST

  None (edit)
Description Dmitri Pal 2012-09-06 09:34:55 EDT
This bug is created as a clone of upstream ticket:
https://fedorahosted.org/sssd/ticket/1499

The sssd-krb5 man page should describe how the keytab entry for TGT validation is selected and what needs to be done make make validation in an environment with trusted domains possible.
Comment 2 Kaushik Banerjee 2013-01-21 06:41:44 EST
Verified in version 1.9.2-74

Manpage of sssd-krb5 verified with following text:
Verify with the help of krb5_keytab that the TGT obtained has not
been spoofed. The keytab is checked for entries sequentially, and
the first entry with a matching realm is used for validation. If no
entry matches the realm, the last entry in the keytab is used. This
process can be used to validate environments using cross-realm
trust by placing the appropriate keytab entry as the last entry or
the only entry in the keytab file.
Comment 3 errata-xmlrpc 2013-02-21 04:36:58 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHSA-2013-0508.html

Note You need to log in before you can comment on or make changes to this bug.