#3240 Smartcard authentication with UPN as logon name might fail
Closed: Fixed Opened by jhrozek.

Ticket was cloned from Red Hat Bugzilla (product Red Hat Enterprise Linux 7): Bug 1389796

Description of problem:
During Smartcard authentication SSSD's PAM responder does not check if the
logon name is a UPN. In general this is not an issue because most login
programs like /bin/logon or sshd canonicalize the name before calling the PAM
stack. Currently it looks that only gdm-password does send the original name
the user entered to the PAM stack (this is good and should not be changed).
Version-Release number of selected component (if applicable):
sssd-1.14.0-43.el7
How reproducible:
Steps to Reproduce:
1. Prepare a system for Smartcard authentication with SSSD but do not enable
the Smartcard support in GDM
2. Try Smartcard authentication and use a UPN which is different from the
actual user name returned by 'getent passwd'
Actual results:
Password prompt is shown
Expected results:
Smartcard PIN prompt should be shown
Additional info:
Issue originally reported in
https://bugzilla.redhat.com/show_bug.cgi?id=1377322

Fields changed

blockedby: =>
blocking: =>
changelog: =>
coverity: =>
design: =>
design_review: => 0
feature_milestone: =>
fedora_test_page: =>
mark: no => 0
milestone: NEEDS_TRIAGE => SSSD 1.15 Beta
patch: => 0
review: True => 0
selected: =>
testsupdated: => 0

Fields changed

milestone: SSSD 1.15.3 => SSSD 1.15.2

Metadata Update from @jhrozek:
- Issue set to the milestone: SSSD 1.15.2

Metadata Update from @jhrozek:
- Custom field design_review reset
- Custom field mark reset
- Custom field patch reset
- Custom field review reset
- Custom field sensitive reset
- Custom field testsupdated reset
- Issue close_status updated to: None
- Issue set to the milestone: SSSD 1.15.3 (was: SSSD 1.15.2)

Metadata Update from @jhrozek:
- Custom field design_review reset
- Custom field mark reset
- Custom field patch reset
- Custom field review reset
- Custom field sensitive reset
- Custom field testsupdated reset
- Issue set to the milestone: SSSD 1.15.4 (was: SSSD 1.15.3)

Metadata Update from @sbose:
- Issue assigned to sbose

https://github.com/SSSD/sssd/pull/271

Metadata Update from @sbose:
- Custom field design_review reset (from false)
- Custom field mark reset (from false)
- Custom field patch reset (from false)
- Custom field review reset (from false)
- Custom field sensitive reset (from false)
- Custom field testsupdated reset (from false)

Metadata Update from @sbose:
- Custom field design_review reset (from false)
- Custom field mark reset (from false)
- Custom field patch adjusted to on (was: false)
- Custom field review reset (from false)
- Custom field sensitive reset (from false)
- Custom field testsupdated reset (from false)

master:

  • 29d063505c07127f7747405b1a61d8f782673645
  • ec9ac22d699a17d590b1d4ba9ba3750eb719f340
  • 870b58a6cc6b5cf92a6503c1578e5c21617c8d40

Metadata Update from @jhrozek:
- Custom field design_review reset (from false)
- Custom field mark reset (from false)
- Custom field review reset (from false)
- Custom field sensitive reset (from false)
- Custom field testsupdated reset (from false)

Metadata Update from @jhrozek:
- Custom field design_review reset (from false)
- Custom field mark reset (from false)
- Custom field review reset (from false)
- Custom field sensitive reset (from false)
- Custom field testsupdated reset (from false)
- Issue set to the milestone: SSSD 1.15.3 (was: SSSD 1.15.4)

Metadata Update from @jhrozek:
- Custom field design_review reset (from false)
- Custom field mark reset (from false)
- Custom field review reset (from false)
- Custom field sensitive reset (from false)
- Custom field testsupdated reset (from false)
- Issue close_status updated to: Fixed
- Issue status updated to: Closed (was: Open)

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/4273

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata