Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-45838

idmap_ad creates an incorrect local krb5.conf in case of trusted domain lookups [rhel-10]

    • samba-4.20.2-103.el10
    • Yes
    • Low
    • Regression
    • sst_idm_sssd
    • ssg_idm
    • 0
    • False
    • Hide

      None

      Show
      None
    • None
    • Red Hat Enterprise Linux
    • None
    • None

      idmap_ad creates an incorrect local krb5.conf in case of trusted domain lookups.

      In case we have idmap_ad and trusted domain and connect to a trusted domain we create a krb5.conf for our realm but with the IP of the trusted domain KDC. Thus we try to get a krbtgt from the trusted domain for our machine account and fail. The trusted domain KDC doesn't know about our machine account.

      We need to look up the KDC IP in this case instead of providing one.

            anschnei@redhat.com Andreas Schneider
            anschnei@redhat.com Andreas Schneider
            Andreas Schneider Andreas Schneider
            Denis Karpelevich Denis Karpelevich
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

              Created:
              Updated: