[SSSD][capaths] SSSD versions earlier than 1.12 do not respect/generate capaths on the IPA client

Solution Verified - Updated -

Issue

This is known issue for transitive trusts. MIT Kerberos requires for non-hierarchical trusts that [capaths] section contains proper map of relationships between the realms.
There is an API to manage this map for IPA KDC driver. For IPA masters, it is written with the help of SSSD for KDC but on IPA clients it is not generated since receiving referrals from KDC was initially considered to be enough. However this has not proven to be enough and the issue is resolved in SSSD 1.12 version, where the map is also written on the IPA client:

commit:
    UTIL: Always write capaths

    We used to only generate the [capaths] section on the IPA server itself,
    when running in a trusted setup. But we also found out that the capaths
    are often required to make SSO fully work, so it's better to always
    generate them.

Environment

RHEL6.6 and earlier versions are affected by this.
The issue is resolved with the RHEL6.7 version of SSSD.

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.