Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-6973

How to set up SSSD authentication against LDAP for OpenShift clusters on Azure to provide SSH access when the cluster is in a bad shape., what is the best way to distribute the sssd configuration LDAP password securely.

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • None
    • MCO
    • False
    • None
    • False
    • Not Selected

      1. Proposed title of this feature request

       RHCOS Integration with LDAP with SSSD.

      2. What is the nature and description of the request?
      The customer is investigating how to set up SSSD authentication against LDAP for OpenShift clusters on Azure to provide SSH access when the cluster is in a bad shape. They are following a blog post from Red Hat, but are unsure of the best way to distribute the sssd configuration LDAP password securely. They are looking for a solution that does not involve creating secrets in machineconfigs or building a custom DaemonSet. They mention that there is an open Red Hat Jira issue (MCO-104) related to this, but there is no public detail available. The customer is seeking clarification on the status of this issue and if it is possible to request a new RFE for the MCO to better handle the distribution of secret files. The business impact is that they need a secure and efficient way to distribute the sssd configuration LDAP password for OpenShift clusters to ensure PCI-DSS compliance.

      3. Why does the customer need this? (List the business requirements here)

      Ongoing improvements for PCI-DSS audits.

      4. List any affected packages or components.

              rhn-support-mrussell Mark Russell
              rhn-support-anehra Abhilasha Nehra
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: