Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-114468

Spam in 'sssd_kcm.log' during normal operations

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • rhel-8.10, rhel-10.1, rhel-9.7
    • sssd
    • rhel-idm
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      When user authenticates against sshd/sftp using GSSAPI/TGT, this triggers unnecessary backtraces in 'sssd_kcm.log'

      Operation flow is as following:
      ```
      KCM operation GEN_NEW
      KCM operation SET_DEFAULT_CACHE
      [kcm_ccdb_uuid_by_name_done] (0x0040): CID#1 Failed to resolve cache by UUID [1432158219]: No credentials available
      KCM operation INITIALIZE
      KCM operation SET_KDC_OFFSET
      KCM operation STORE
      KCM operation DESTROY
      ```

      Note that here the user doesn't login per se, IIUC, it is 'sshd' who stores creds for the duration of a (likely) SFTP session.

      Spammy message seen is generated during handling of `SET_DEFAULT_CACHE`.
      First of all, there is a mistype:
      https://github.com/SSSD/sssd/blob/5aa8c23a6b2c7e1c4087a88b33ac8088f57cefd3/src/responder/kcm/kcmsrv_ccache.c#L1248

      • this should log "... by name", not "... by UUID" (copy & paste error).

      Moreover, I don't think it's worth SSSDBG_OP_FAILURE.
      Imo, it's pretty much expected that there is no container for any name in the store that was just generated ('GEN_NEW'), and thus not worth a message on the default log level.

              sssd-maint SSSD Maintainers
              atikhono@redhat.com Alexey Tikhonov
              Alexey Tikhonov Alexey Tikhonov
              SSSD QE SSSD QE
              inactive-user inactive-user
              Votes:
              0 Vote for this issue
              Watchers:
              11 Start watching this issue

                Created:
                Updated: