#1190 SSSD will need to be able to provide a prompter callback to libkrb5
Closed: Invalid Opened by nalin.

The way PKINIT plugins currently work (see ticket #546, which asks that that be supported), the plugin will attempt to use the prompter callback, which the calling application will have supplied, to ask for information such as smart card PINs and the passphrase for encrypted key storage. Right now the krb5 provider doesn't appear to supply a callback, and it will need to in order to support this case. I'm adding this here to allow it to be tracked as a separable item.


Fields changed

milestone: NEEDS_TRIAGE => SSSD Kerberos Improvements Feature

Fields changed

rhbz: => 0

This has a tight relation to the work Nathaniel is doing for client side of the AuthHub project. Once the AuthHub client code merged to MIT tree and the new responder interface is implemented we would need utilize this interface in SSSD for OTP and CS authentication.

proposed_priority: => Core
type: enhancement => task

Moving all the features planned for 1.10 release into 1.10 beta.

milestone: SSSD Kerberos Improvements Feature => SSSD 1.10 beta

Fields changed

priority: major => critical

Fields changed

design: =>
design_review: => 0
fedora_test_page: =>
selected: => Not need

Moving tickets that are not a priority for SSSD 1.10 into the next release.

milestone: SSSD 1.10 beta => SSSD 1.11 beta

Related to SC and OTP work.

changelog: =>
milestone: SSSD 1.12 beta => Interim Bucket
priority: critical => major
review: => 0

Fields changed

milestone: Interim Bucket => SSSD 1.12 beta

Should be solved together with ticket #2335 which is in 1.12 in at the moment.

Fields changed

milestone: SSSD 1.12 beta => SSSD 1.12.1

Mass-moving all tickets that didn't make 1.12.1 into 1.12.2

milestone: SSSD 1.12.1 => SSSD 1.12.2

We need to do a release as requested by downstream. Moving tickets that are not fixed already or very close to acking to 1.12.3

milestone: SSSD 1.12.2 => SSSD 1.12.3

We discussed some time ago that in 1.12 we only remove the OTP password from the PAM stack. This ticket belongs to 1.13.

mark: => 0
milestone: SSSD 1.12.3 => SSSD 1.13 beta

Let's evaluate whether we need this during Sumit's smart card work.

owner: somebody => sbose

Sumit will work on pkinit after smartcards are done.

milestone: SSSD 1.13 beta => SSSD 1.13 backlog
sensitive: => 0

OTP was implemented already including prompting, this ticket can be closed.

resolution: => invalid
status: new => closed

Metadata Update from @nalin:
- Issue assigned to sbose
- Issue set to the milestone: SSSD 1.13 backlog

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/2232

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata