Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-4981

p11_child currently has an infinite timeout

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • None
    • rhel-8.5.0
    • sssd
    • None
    • Moderate
    • rhel-sst-idm-sssd
    • ssg_idm
    • 0
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • If docs needed, set a value
    • None

      Description of problem:

      p11_child currently has an infinite timeout which is causing OCSP requests to fail on semi-disconnected systems with multi certificates, such as a CAC.

      Version-Release number of selected component (if applicable):

      OS: Red Hat Enterprise Linux release 8.5 (Ootpa)
      SSSD: sssd-2.5.2-2.el8_5.3.x86_64
      p11-kit: p11-kit-0.23.22-1.el8.x86_64

      How reproducible:

      Consistently.

      Steps to Reproduce:
      1. Prepare system for smart card login with a CAC.
      2. Disconnect from the network
      3. Attempt to login.

      Actual results:

      The certificate menu is presented even though the cert is specified, and login fails after PIN entry.

      Expected results:

      The system skips the OCSP check (if configured) due to connection timeout and proceeds onward.

              sssd-maint SSSD Maintainers
              rhn-support-ccallaha Chance Callahan
              SSSD Maintainers SSSD Maintainers
              SSSD QE SSSD QE
              Votes:
              0 Vote for this issue
              Watchers:
              14 Start watching this issue

                Created:
                Updated: