Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-113111

Including innapropriate IPv6 addresses in dyndns_update

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • rhel-10.2
    • rhel-9.7
    • sssd
    • No
    • None
    • rhel-idm
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified

      Tested in version 2.8.2

      SSSD is including IPv6 addresses marked deprecated via dyndns_update, so when a host's prefix changes, both the old and new address are included in the update, causing the DNS server to sometimes distribute the deprecated address, preventing connectivity. I have not tested if it also erroneously includes addresses marked temporary, because all of my domain joined machines currently have this disabled, however I am concerned it may do this as well.

      I found the related bug [1991](https://github.com/SSSD/sssd/issues/1991) from a much older version, where even link local addresses were being included. Fortunately that issue is no longer present.

      I found the related issue [5662](https://github.com/SSSD/sssd/issues/5662) where because address changes do not result in an interface drop, they do not trigger dyndns_update. This is obviously a different issue, but it also causes IPv6 addressing information in the DC to be inaccurate, it just has eventual consistency.

              thalman@redhat.com Tomas Halman
              aboscatt@redhat.com Andre Boscatto
              SSSD Maintainers SSSD Maintainers
              Dan Lavu Dan Lavu
              inactive-user inactive-user
              Votes:
              0 Vote for this issue
              Watchers:
              12 Start watching this issue

                Created:
                Updated: