Skip to content

KRB5: read keytab copy in offline mode too#8671

Merged
alexey-tikhonov merged 1 commit into
SSSD:masterfrom
alexey-tikhonov:read-keytab-offline
May 11, 2026
Merged

KRB5: read keytab copy in offline mode too#8671
alexey-tikhonov merged 1 commit into
SSSD:masterfrom
alexey-tikhonov:read-keytab-offline

Conversation

@alexey-tikhonov

Copy link
Copy Markdown
Member

The process can transition from offline pre-auth to online auth within the same invocation.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request modifies the privileged_krb5_setup function in krb5_child.c to allow keytab setup even when offline, while adding a guard to skip FAST configuration in offline mode. Feedback suggests that skipping FAST setup entirely when offline could lead to security issues or authentication failures if the process transitions to online mode later, as the FAST options would not be properly initialized.

Comment thread src/providers/krb5/krb5_child.c
@alexey-tikhonov
alexey-tikhonov marked this pull request as ready for review May 6, 2026 09:52
@alexey-tikhonov

Copy link
Copy Markdown
Member Author

@ikerexxe ikerexxe left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@sumit-bose sumit-bose left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi,

thank you for the fix to solve the regression, ACK.

Nevertheless it might be good to rethink the role of krb5_child if the SSSD backend is offline.

bye,
Sumit

@sumit-bose sumit-bose added coverity Trigger a coverity scan and removed coverity Trigger a coverity scan labels May 8, 2026
@sumit-bose

Copy link
Copy Markdown
Contributor

Coverity was green.

The process can transition from offline pre-auth to online auth within
the same invocation.

Reviewed-by: Iker Pedrosa <[email protected]>
Reviewed-by: Sumit Bose <[email protected]>
@sssd-bot

Copy link
Copy Markdown
Contributor

The pull request was accepted by @alexey-tikhonov with the following PR CI status:


🟢 CodeQL (success)
🟢 osh-diff-scan:fedora-rawhide-x86_64:upstream (success)
🟢 rpm-build:centos-stream-10-x86_64:upstream (success)
🟢 rpm-build:fedora-42-x86_64:upstream (success)
🟢 rpm-build:fedora-43-x86_64:upstream (success)
🟢 rpm-build:fedora-44-x86_64:upstream (success)
🟢 rpm-build:fedora-rawhide-x86_64:upstream (success)
🟢 Analyze (target) / cppcheck (success)
🟢 Build / freebsd (success)
🟢 Build / make-distcheck (success)
🟢 ci / intgcheck (centos-10) (success)
🟢 ci / intgcheck (fedora-42) (success)
🟢 ci / intgcheck (fedora-43) (success)
🟢 ci / intgcheck (fedora-44) (success)
🟢 ci / intgcheck (fedora-45) (success)
🟢 ci / prepare (success)
🟢 ci / system (centos-10) (success)
🟢 ci / system (fedora-42) (success)
🟢 ci / system (fedora-43) (success)
🔴 ci / system (fedora-44) (failure)
🟢 ci / system (fedora-45) (success)
➖ Coverity scan / coverity (skipped)
🟢 Static code analysis / codeql (success)
🟢 Static code analysis / pre-commit (success)
🟢 Static code analysis / python-system-tests (success)


There are unsuccessful or unfinished checks. Make sure that the failures are not related to this pull request before merging.

@sssd-bot
sssd-bot force-pushed the read-keytab-offline branch from f9effbb to 3c569bd Compare May 11, 2026 06:38
@alexey-tikhonov
alexey-tikhonov merged commit b070171 into SSSD:master May 11, 2026
10 of 15 checks passed
@alexey-tikhonov alexey-tikhonov linked an issue Jun 5, 2026 that may be closed by this pull request
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Permission denied in krb5_child on keytab.

4 participants