RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Bug 910898 - [RFE] Make use of Fallback SASL mappings
Summary: [RFE] Make use of Fallback SASL mappings
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: ipa
Version: 7.0
Hardware: Unspecified
OS: Unspecified
medium
unspecified
Target Milestone: rc
: ---
Assignee: Martin Kosek
QA Contact: IDM QE LIST
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-02-13 20:06 UTC by Namita Soman
Modified: 2014-06-18 00:06 UTC (History)
2 users (show)

Fixed In Version: ipa-3.2.2-1.el7
Doc Type: Enhancement
Doc Text:
Clone Of:
Environment:
Last Closed: 2014-06-13 09:47:44 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Namita Soman 2013-02-13 20:06:24 UTC
This bug is created as a clone of upstream ticket:
https://fedorahosted.org/freeipa/ticket/3330

In https://fedorahosted.org/389/ticket/534 the DS team has implemented SASL mapping priority and fallback.

We need to make use of this feature (which means change configuration of cn=config on upgrade probably) for 2 cases:

1. Fallback to account in cn=config for automatic recovery on initialization failures see ticket: #3214

2. Mapping external users like trusted users from AD trusted domain to a common placeholder entry which will allow them minimal access to IPAs LDAP server and web framework.

Comment 1 Martin Kosek 2013-06-27 15:11:38 UTC
master:
ea7db35b6224b8c67b789ac1eb35c9bc6c3eb6b5 Enable SASL mapping fallback.

ipa-3-2:
2945bc1f725648e5dc76effb50903ef9beb168db Enable SASL mapping fallback.

Comment 3 Namita Soman 2014-02-20 13:50:07 UTC
Please provide steps to verify this

Comment 4 Martin Kosek 2014-02-24 16:03:12 UTC
I think there are no functional changes besides enabling SASL mapping fallback. For now, we use the basic functionality and mapping we had there before. We want to use additional mapping in the future (7.1 or later).

Thus, to verify what is in now, you can check that these settings are enabled:

dn: cn=config
nsslapd-sasl-mapping-fallback: on

dn: cn=Full Principal,cn=mapping,cn=sasl,cn=config
nsSaslMapPriority: 10

dn: cn=Name Only,cn=mapping,cn=sasl,cn=config
nsSaslMapPriority: 10

Comment 5 Namita Soman 2014-02-24 19:12:22 UTC
Verified using ipa-server-3.3.3-18.el7.x86_64

# ldapsearch -LLL -D "cn=directory manager" -w Secret123 -b "cn=config" -s base nsslapd-sasl-mapping-fallback
dn: cn=config
nsslapd-sasl-mapping-fallback: on


# ldapsearch -LLL -D "cn=directory manager" -w Secret123 -b "cn=Full Principal,cn=mapping,cn=sasl,cn=config" -s base nsSaslMapPriority
dn: cn=Full Principal,cn=mapping,cn=sasl,cn=config
nsSaslMapPriority: 10

# ldapsearch -LLL -D "cn=directory manager" -w Secret123 -b "cn=Name Only,cn=mapping,cn=sasl,cn=config" -s base nsSaslMapPriority
dn: cn=Name Only,cn=mapping,cn=sasl,cn=config
nsSaslMapPriority: 10

Comment 7 Ludek Smid 2014-06-13 09:47:44 UTC
This request was resolved in Red Hat Enterprise Linux 7.0.

Contact your manager or support representative in case you have further questions about the request.


Note You need to log in before you can comment on or make changes to this bug.