Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-4957

RFE: check for krbLastSuccessfulAuth being enabled

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: Generate New Ti...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • ipa-healthcheck-0.16-6.el9
    • None
    • 7
    • rhel-idm-ipa
    • ssg_idm
    • 6
    • 8
    • 2
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • 2025-Q1-Bravo-S4, 2025-Q1-Bravo-S5, 2025-Q1-Bravo-S6, 2025-Q2-Bravo-S2, 2025-Q2-Alpha-S4, 2025-Q2-Alpha-S5, 2025-Q2-Alpha-S6
    • Enhancement
    • Hide
      .`Healthcheck` warns if `krbLastSuccessfulAuth` is enabled

      Enabling the `krbLastSuccessfulAuth` setting in the `ipaConfigString` attribute can lead to performance issues if large numbers of users are authenticating at the same time. Therefore, it is disabled by default. With this update, `Healthcheck` displays a message if `krbLastSuccessfulAuth` is enabled, warning about the possible performance problems.
      Show
      .`Healthcheck` warns if `krbLastSuccessfulAuth` is enabled Enabling the `krbLastSuccessfulAuth` setting in the `ipaConfigString` attribute can lead to performance issues if large numbers of users are authenticating at the same time. Therefore, it is disabled by default. With this update, `Healthcheck` displays a message if `krbLastSuccessfulAuth` is enabled, warning about the possible performance problems.
    • Done
    • None
    • 57,005

      Description of problem:

      We're still seeing cases where krbLastSuccessfulAuth is causing performance issues.

      I'll quote the upstream issue:
      https://pagure.io/freeipa/issue/5313
      "Even if this attribute is skipped in fractional replication, all the changes
      are sent to changelog and replication has to browse them to decide whether to
      skip or not."

      Would it be possible to check for this?

      Version-Release number of selected component (if applicable):

      Current git main, considering:
      $ grep -nr krbLastSuccessfulAuth .
      $ git log | head -n1
      commit 11c77a199304fba4f430e9386593477f37652f23

              rhn-engineering-rcrit Rob Crittenden
              rh-support-fcami François Cami
              Rob Crittenden Rob Crittenden
              Sudhir Menon Sudhir Menon
              David Vozenilek David Vozenilek
              Votes:
              0 Vote for this issue
              Watchers:
              10 Start watching this issue

                Created:
                Updated:
                Resolved: