|
|
ca1eb8 |
From 660ef95e36ad73b4715656a4207aeb499ac96d16 Mon Sep 17 00:00:00 2001
|
|
|
ca1eb8 |
From: Sumit Bose <sbose@redhat.com>
|
|
|
ca1eb8 |
Date: Thu, 24 May 2018 17:15:38 +0200
|
|
|
ca1eb8 |
Subject: [PATCH] AD/IPA: Create kdcinfo file for sub-domains
|
|
|
ca1eb8 |
|
|
|
ca1eb8 |
With this patch kdcinfo files are created for sub-domains by the AD
|
|
|
ca1eb8 |
provider and by the IPA provider on the IPA servers
|
|
|
ca1eb8 |
(ipa_server_mode=True).
|
|
|
ca1eb8 |
|
|
|
ca1eb8 |
Related to https://pagure.io/SSSD/sssd/issue/3652
|
|
|
ca1eb8 |
Reviewed-by: Jakub Hrozek <jhrozek@redhat.com>
|
|
|
ca1eb8 |
|
|
|
ca1eb8 |
(cherry picked from commit cc7922755dac53c69558ba060b309ac48ae82783)
|
|
|
ca1eb8 |
---
|
|
|
ca1eb8 |
src/providers/ad/ad_common.c | 9 +++++++++
|
|
|
ca1eb8 |
src/providers/ad/ad_common.h | 1 +
|
|
|
ca1eb8 |
src/providers/ad/ad_init.c | 1 +
|
|
|
ca1eb8 |
src/providers/ad/ad_subdomains.c | 17 ++++++++++++++---
|
|
|
ca1eb8 |
src/providers/ipa/ipa_subdomains_server.c | 16 ++++++++++++++--
|
|
|
ca1eb8 |
5 files changed, 39 insertions(+), 5 deletions(-)
|
|
|
ca1eb8 |
|
|
|
ca1eb8 |
diff --git a/src/providers/ad/ad_common.c b/src/providers/ad/ad_common.c
|
|
|
ca1eb8 |
index be7791e6cc2527d45d3e2ff50294f9b98106ffae..0aea985e00faa996643fd7e7630d4264fb6cf233 100644
|
|
|
ca1eb8 |
--- a/src/providers/ad/ad_common.c
|
|
|
ca1eb8 |
+++ b/src/providers/ad/ad_common.c
|
|
|
ca1eb8 |
@@ -727,6 +727,7 @@ ad_failover_init(TALLOC_CTX *mem_ctx, struct be_ctx *bectx,
|
|
|
ca1eb8 |
const char *ad_service,
|
|
|
ca1eb8 |
const char *ad_gc_service,
|
|
|
ca1eb8 |
const char *ad_domain,
|
|
|
ca1eb8 |
+ bool use_kdcinfo,
|
|
|
ca1eb8 |
struct ad_service **_service)
|
|
|
ca1eb8 |
{
|
|
|
ca1eb8 |
errno_t ret;
|
|
|
ca1eb8 |
@@ -762,6 +763,14 @@ ad_failover_init(TALLOC_CTX *mem_ctx, struct be_ctx *bectx,
|
|
|
ca1eb8 |
goto done;
|
|
|
ca1eb8 |
}
|
|
|
ca1eb8 |
|
|
|
ca1eb8 |
+ /* Set flag that controls whether we want to write the
|
|
|
ca1eb8 |
+ * kdcinfo files at all
|
|
|
ca1eb8 |
+ */
|
|
|
ca1eb8 |
+ service->krb5_service->write_kdcinfo = use_kdcinfo;
|
|
|
ca1eb8 |
+ DEBUG(SSSDBG_CONF_SETTINGS, "write_kdcinfo for realm %s set to %s\n",
|
|
|
ca1eb8 |
+ krb5_realm,
|
|
|
ca1eb8 |
+ service->krb5_service->write_kdcinfo ? "true" : "false");
|
|
|
ca1eb8 |
+
|
|
|
ca1eb8 |
ret = be_fo_add_service(bectx, ad_service, ad_user_data_cmp);
|
|
|
ca1eb8 |
if (ret != EOK) {
|
|
|
ca1eb8 |
DEBUG(SSSDBG_CRIT_FAILURE, "Failed to create failover service!\n");
|
|
|
ca1eb8 |
diff --git a/src/providers/ad/ad_common.h b/src/providers/ad/ad_common.h
|
|
|
ca1eb8 |
index 6eb2ba7e9a7350d1924c45d33d8c332073767a34..dd440da33d48a5820c665f43908d1e1fb18171a6 100644
|
|
|
ca1eb8 |
--- a/src/providers/ad/ad_common.h
|
|
|
ca1eb8 |
+++ b/src/providers/ad/ad_common.h
|
|
|
ca1eb8 |
@@ -144,6 +144,7 @@ ad_failover_init(TALLOC_CTX *mem_ctx, struct be_ctx *ctx,
|
|
|
ca1eb8 |
const char *ad_service,
|
|
|
ca1eb8 |
const char *ad_gc_service,
|
|
|
ca1eb8 |
const char *ad_domain,
|
|
|
ca1eb8 |
+ bool use_kdcinfo,
|
|
|
ca1eb8 |
struct ad_service **_service);
|
|
|
ca1eb8 |
|
|
|
ca1eb8 |
errno_t
|
|
|
ca1eb8 |
diff --git a/src/providers/ad/ad_init.c b/src/providers/ad/ad_init.c
|
|
|
ca1eb8 |
index b19624782000c5c7c65e766e3e01ff6ac3ab7adb..637efb761c1cf87b0a2c2b1c19b00ea0bbbe161f 100644
|
|
|
ca1eb8 |
--- a/src/providers/ad/ad_init.c
|
|
|
ca1eb8 |
+++ b/src/providers/ad/ad_init.c
|
|
|
ca1eb8 |
@@ -159,6 +159,7 @@ static errno_t ad_init_options(TALLOC_CTX *mem_ctx,
|
|
|
ca1eb8 |
ret = ad_failover_init(ad_options, be_ctx, ad_servers, ad_backup_servers,
|
|
|
ca1eb8 |
ad_realm, AD_SERVICE_NAME, AD_GC_SERVICE_NAME,
|
|
|
ca1eb8 |
dp_opt_get_string(ad_options->basic, AD_DOMAIN),
|
|
|
ca1eb8 |
+ false, /* will be set in ad_get_auth_options() */
|
|
|
ca1eb8 |
&ad_options->service);
|
|
|
ca1eb8 |
if (ret != EOK) {
|
|
|
ca1eb8 |
DEBUG(SSSDBG_FATAL_FAILURE, "Failed to init AD failover service: "
|
|
|
ca1eb8 |
diff --git a/src/providers/ad/ad_subdomains.c b/src/providers/ad/ad_subdomains.c
|
|
|
ca1eb8 |
index 74b9f075174b1eaa6c5b5dcbaf609600ef197b52..84886e920b37f8803d85ce0903b74e6c809a8904 100644
|
|
|
ca1eb8 |
--- a/src/providers/ad/ad_subdomains.c
|
|
|
ca1eb8 |
+++ b/src/providers/ad/ad_subdomains.c
|
|
|
ca1eb8 |
@@ -249,6 +249,7 @@ ad_subdom_ad_ctx_new(struct be_ctx *be_ctx,
|
|
|
ca1eb8 |
const char *hostname;
|
|
|
ca1eb8 |
const char *keytab;
|
|
|
ca1eb8 |
char *subdom_conf_path;
|
|
|
ca1eb8 |
+ bool use_kdcinfo = false;
|
|
|
ca1eb8 |
|
|
|
ca1eb8 |
realm = dp_opt_get_cstring(id_ctx->ad_options->basic, AD_KRB5_REALM);
|
|
|
ca1eb8 |
hostname = dp_opt_get_cstring(id_ctx->ad_options->basic, AD_HOSTNAME);
|
|
|
ca1eb8 |
@@ -296,9 +297,19 @@ ad_subdom_ad_ctx_new(struct be_ctx *be_ctx,
|
|
|
ca1eb8 |
servers = dp_opt_get_string(ad_options->basic, AD_SERVER);
|
|
|
ca1eb8 |
backup_servers = dp_opt_get_string(ad_options->basic, AD_BACKUP_SERVER);
|
|
|
ca1eb8 |
|
|
|
ca1eb8 |
- ret = ad_failover_init(ad_options, be_ctx, servers, backup_servers, realm,
|
|
|
ca1eb8 |
- service_name, gc_service_name,
|
|
|
ca1eb8 |
- subdom->name, &ad_options->service);
|
|
|
ca1eb8 |
+ if (id_ctx->ad_options->auth_ctx != NULL
|
|
|
ca1eb8 |
+ && id_ctx->ad_options->auth_ctx->opts != NULL) {
|
|
|
ca1eb8 |
+ use_kdcinfo = dp_opt_get_bool(id_ctx->ad_options->auth_ctx->opts,
|
|
|
ca1eb8 |
+ KRB5_USE_KDCINFO);
|
|
|
ca1eb8 |
+ }
|
|
|
ca1eb8 |
+
|
|
|
ca1eb8 |
+ DEBUG(SSSDBG_TRACE_ALL,
|
|
|
ca1eb8 |
+ "Init failover for [%s][%s] with use_kdcinfo [%s].\n",
|
|
|
ca1eb8 |
+ subdom->name, subdom->realm, use_kdcinfo ? "true" : "false");
|
|
|
ca1eb8 |
+
|
|
|
ca1eb8 |
+ ret = ad_failover_init(ad_options, be_ctx, servers, backup_servers,
|
|
|
ca1eb8 |
+ subdom->realm, service_name, gc_service_name,
|
|
|
ca1eb8 |
+ subdom->name, use_kdcinfo, &ad_options->service);
|
|
|
ca1eb8 |
if (ret != EOK) {
|
|
|
ca1eb8 |
DEBUG(SSSDBG_OP_FAILURE, "Cannot initialize AD failover\n");
|
|
|
ca1eb8 |
talloc_free(ad_options);
|
|
|
ca1eb8 |
diff --git a/src/providers/ipa/ipa_subdomains_server.c b/src/providers/ipa/ipa_subdomains_server.c
|
|
|
ca1eb8 |
index 1e53e7a951189120fcf3f438362e902a5a8f6d97..02577c92159d099a04cbd5cee80064309466db93 100644
|
|
|
ca1eb8 |
--- a/src/providers/ipa/ipa_subdomains_server.c
|
|
|
ca1eb8 |
+++ b/src/providers/ipa/ipa_subdomains_server.c
|
|
|
ca1eb8 |
@@ -228,6 +228,7 @@ ipa_ad_ctx_new(struct be_ctx *be_ctx,
|
|
|
ca1eb8 |
struct sdap_domain *sdom;
|
|
|
ca1eb8 |
errno_t ret;
|
|
|
ca1eb8 |
const char *extra_attrs;
|
|
|
ca1eb8 |
+ bool use_kdcinfo = false;
|
|
|
ca1eb8 |
|
|
|
ca1eb8 |
ad_domain = subdom->name;
|
|
|
ca1eb8 |
DEBUG(SSSDBG_TRACE_LIBS, "Setting up AD subdomain %s\n", subdom->name);
|
|
|
ca1eb8 |
@@ -284,12 +285,23 @@ ipa_ad_ctx_new(struct be_ctx *be_ctx,
|
|
|
ca1eb8 |
ad_servers = dp_opt_get_string(ad_options->basic, AD_SERVER);
|
|
|
ca1eb8 |
ad_backup_servers = dp_opt_get_string(ad_options->basic, AD_BACKUP_SERVER);
|
|
|
ca1eb8 |
|
|
|
ca1eb8 |
+ if (id_ctx->ipa_options != NULL && id_ctx->ipa_options->auth != NULL) {
|
|
|
ca1eb8 |
+ use_kdcinfo = dp_opt_get_bool(id_ctx->ipa_options->auth,
|
|
|
ca1eb8 |
+ KRB5_USE_KDCINFO);
|
|
|
ca1eb8 |
+ }
|
|
|
ca1eb8 |
+
|
|
|
ca1eb8 |
+ DEBUG(SSSDBG_TRACE_ALL,
|
|
|
ca1eb8 |
+ "Init failover for [%s][%s] with use_kdcinfo [%s].\n",
|
|
|
ca1eb8 |
+ subdom->name, subdom->realm, use_kdcinfo ? "true" : "false");
|
|
|
ca1eb8 |
+
|
|
|
ca1eb8 |
/* Set KRB5 realm to same as the one of IPA when IPA
|
|
|
ca1eb8 |
* is able to attach PAC. For testing, use hardcoded. */
|
|
|
ca1eb8 |
+ /* Why? */
|
|
|
ca1eb8 |
ret = ad_failover_init(ad_options, be_ctx, ad_servers, ad_backup_servers,
|
|
|
ca1eb8 |
- id_ctx->server_mode->realm,
|
|
|
ca1eb8 |
+ subdom->realm,
|
|
|
ca1eb8 |
service_name, gc_service_name,
|
|
|
ca1eb8 |
- subdom->name, &ad_options->service);
|
|
|
ca1eb8 |
+ subdom->name, use_kdcinfo,
|
|
|
ca1eb8 |
+ &ad_options->service);
|
|
|
ca1eb8 |
if (ret != EOK) {
|
|
|
ca1eb8 |
DEBUG(SSSDBG_OP_FAILURE, "Cannot initialize AD failover\n");
|
|
|
ca1eb8 |
talloc_free(ad_options);
|
|
|
ca1eb8 |
--
|
|
|
ca1eb8 |
2.17.1
|
|
|
ca1eb8 |
|