https://bugzilla.redhat.com/show_bug.cgi?id=2351336
Bug ID: 2351336
Summary: /etc/krb5.conf.d/enable_sssd_conf_dir is mistakenly in
package sssd-krb5, not in sssd-krb5-common
Product: Fedora
Version: 41
Hardware: x86_64
OS: Linux
Status: NEW
Component: sssd
Severity: medium
Assignee: sssd-maintainers(a)lists.fedoraproject.org
Reporter: hey(a)runiq.de
QA Contact: extras-qa(a)fedoraproject.org
CC: abokovoy(a)redhat.com, atikhono(a)redhat.com,
lslebodn(a)redhat.com, pbrezina(a)redhat.com,
sbose(a)redhat.com, ssorce(a)redhat.com,
sssd-maintainers(a)lists.fedoraproject.org
Target Milestone: ---
Classification: Fedora
I have used realmd to join a host to an Active Directory domain. Realmd uses
sssd-ad for this, which pulls in sssd-krb5-common but _not_ sssd-krb5.
Unfortunately, sssd-krb5-common does not install the snippet
/etc/krb5.conf.d/enable_sssd_conf_dir. This results in SSH refusing
gssapi-with-mic authentication.
When I additionally install the sssd-krb5 package (which includes the snippet),
or create the snippet manually, SSH logins use my SSSD config and GSSAPI
authentication goes through.
Reproducible: Always
Steps to Reproduce:
1. Install realmd on a host
2. Join host to Active Directory domain
3. Enable SSH daemon
4. ssh -l user@realm -o preferredauthentications=gssapi-with-mic host
Actual Results:
Authentication is denied, no SSH session opened
Expected Results:
Authentication goes through, SSH session is opened
--
You are receiving this mail because:
You are on the CC list for the bug.
You are the assignee for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2351336
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…