The way PKINIT plugins currently work (see ticket #546, which asks that that be supported), the plugin will attempt to use the prompter callback, which the calling application will have supplied, to ask for information such as smart card PINs and the passphrase for encrypted key storage. Right now the krb5 provider doesn't appear to supply a callback, and it will need to in order to support this case. I'm adding this here to allow it to be tracked as a separable item.
Fields changed
milestone: NEEDS_TRIAGE => SSSD Kerberos Improvements Feature
rhbz: => 0
This has a tight relation to the work Nathaniel is doing for client side of the AuthHub project. Once the AuthHub client code merged to MIT tree and the new responder interface is implemented we would need utilize this interface in SSSD for OTP and CS authentication.
proposed_priority: => Core type: enhancement => task
Moving all the features planned for 1.10 release into 1.10 beta.
milestone: SSSD Kerberos Improvements Feature => SSSD 1.10 beta
priority: major => critical
design: => design_review: => 0 fedora_test_page: => selected: => Not need
Moving tickets that are not a priority for SSSD 1.10 into the next release.
milestone: SSSD 1.10 beta => SSSD 1.11 beta
Related to SC and OTP work.
changelog: => milestone: SSSD 1.12 beta => Interim Bucket priority: critical => major review: => 0
milestone: Interim Bucket => SSSD 1.12 beta
Should be solved together with ticket #2335 which is in 1.12 in at the moment.
milestone: SSSD 1.12 beta => SSSD 1.12.1
Mass-moving all tickets that didn't make 1.12.1 into 1.12.2
milestone: SSSD 1.12.1 => SSSD 1.12.2
We need to do a release as requested by downstream. Moving tickets that are not fixed already or very close to acking to 1.12.3
milestone: SSSD 1.12.2 => SSSD 1.12.3
We discussed some time ago that in 1.12 we only remove the OTP password from the PAM stack. This ticket belongs to 1.13.
mark: => 0 milestone: SSSD 1.12.3 => SSSD 1.13 beta
Let's evaluate whether we need this during Sumit's smart card work.
owner: somebody => sbose
Sumit will work on pkinit after smartcards are done.
milestone: SSSD 1.13 beta => SSSD 1.13 backlog sensitive: => 0
OTP was implemented already including prompting, this ticket can be closed.
resolution: => invalid status: new => closed
Metadata Update from @nalin: - Issue assigned to sbose - Issue set to the milestone: SSSD 1.13 backlog
SSSD is moving from Pagure to Github. This means that new issues and pull requests will be accepted only in SSSD's github repository.
This issue has been cloned to Github and is available here: - https://github.com/SSSD/sssd/issues/2232
If you want to receive further updates on the issue, please navigate to the github issue and click on subscribe button.
subscribe
Thank you for understanding. We apologize for all inconvenience.