Bug 970678 - Document the KrbLocalUserMapping option in README
Document the KrbLocalUserMapping option in README
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: mod_auth_kerb (Show other bugs)
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: Web Stack Team
Filip Holec
Depends On:
  Show dependency treegraph
Reported: 2013-06-04 10:53 EDT by Jan Pazdziora
Modified: 2016-04-18 06:25 EDT (History)
6 users (show)

See Also:
Fixed In Version: mod_auth_kerb-5.4-12.el6
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: 970547
Last Closed: 2014-10-14 03:44:08 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2014:1557 normal SHIPPED_LIVE mod_auth_kerb bug fix update 2014-10-13 21:21:20 EDT

  None (edit)
Description Jan Pazdziora 2013-06-04 10:53:58 EDT
+++ This bug was initially created as a clone of Bug #970547 +++

Description of problem:

When you have a web service using normal basic authentication, your logins will look like "alice" and "bob". When you then enable mod_auth_kerb on that httpd server, the logged in user will be "alice@REALM.COM" and "bob@REALM.COM". Which are completely different users in that web application's database so after using SPNEGO, people will not see their data.

It is necessary to use a

   KrbLocalUserMapping On

directive which is undocumented anywhere in the mod_auth_kerb documentation beyond on line in the Changes file in the mod_auth_kerb-5.4.tar.gz:

   *implemented KrbLocalUserMapping i.e. to strip @REALM from username for further use

Version-Release number of selected component (if applicable):


How reproducible:


Steps to Reproduce:
1. Enable mod_auth_kerb and try the user names not to have the @REALM so that it matches the basic authentication.
2. Try to find the documentation.

Actual results:

You will only find KrbLocalUserMapping (which is what you want) on Stack Overflow.

Expected results:

The directive will also be in /usr/share/doc/mod_auth_kerb-5.4/README.

Additional info:

Basically, please amend the README shipped with the module. Of course, getting it to upstream as well (not just Fedora but module's upstream) would be the best.
Comment 3 RHEL Product and Program Management 2014-03-25 20:19:08 EDT
This request was evaluated by Red Hat Product Management for
inclusion in a Red Hat Enterprise Linux release.  Product
Management has requested further review of this request by
Red Hat Engineering, for potential inclusion in a Red Hat
Enterprise Linux release for currently deployed products.
This request is not yet committed for inclusion in a release.
Comment 9 errata-xmlrpc 2014-10-14 03:44:08 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.