#6561 CVE-2016-7030 freeipa: ipa: DoS attack against kerberized services by abusing password policy
Closed: Fixed Opened by mbasti.

Ticket was cloned from Red Hat Bugzilla (product Fedora): Bug 1404690

This is an automatically created tracking bug!  It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s).  This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one tracking bug has been filed, please correct all affected versions at
the same time.  If you need to fix the versions independent of each other,
you may clone this bug as appropriate.
[bug automatically created by: add-tracking-bugs]

master:

  • 6f1d927467e7907fd1991f88388d96c67c9bff61 password policy: Add explicit default password policy for hosts and services
  • b1a20599c4f9fdcd208998694185b65460126703 tests: Expect krbpwdpolicyreference in result of {host,service}-{find,show} --all

ipa-4-4:

  • 08e7af9f0f8acac3dcd8dde1eee53261e5d25f1f password policy: Add explicit default password policy for hosts and services
  • 171bc3e6853f905184584e414cefa4f7296c02ea tests: Expect krbpwdpolicyreference in result of {host,service}-{find,show} --all

ipa-4-3:

  • 42263a5a729096135702c0b974f255a058c0cdaf password policy: Add explicit default password policy for hosts and services

This patch breaks upgrade

Linked to Bugzilla bug: https://bugzilla.redhat.com/show_bug.cgi?id=1404910 (Red Hat Enterprise Linux 7)

Fix for upgrade pushed to

ipa-4-3:

  • b9b919e127c453eda02ea142d7cd80c16aa5ca31 ipa-kdb: search for password policies globally

ipa-4-4:

  • 84f6df6349b5c412467746777e905d9e4f8792ca ipa-kdb: search for password policies globally

master:

  • 73f33569c8893610e246b2f44a7aeaec872b37e6 ipa-kdb: search for password policies globally

More commits with tests coming soon

test cases for kadmin pushed to:

master:

  • f59673506493e0199c17000538adb7c80b477aa0 Make kadmin family of functions return the result of ipautil.run
  • d95bdbbfd505dde1348413fc7a1233ac834ce344 Add a basic test suite for kadmin.local interface

ipa-4-4:

  • f0f48ec14f3ff55852393927533ffd253cb5a04b Make kadmin family of functions return the result of ipautil.run
  • e02323c1c3b3c3dadd57d9f1885ec1af046718de Add a basic test suite for kadmin.local interface

test cases for kadmin pushed to:

master:

  • f59673506493e0199c17000538adb7c80b477aa0 Make kadmin family of functions return the result of ipautil.run
  • d95bdbbfd505dde1348413fc7a1233ac834ce344 Add a basic test suite for kadmin.local interface

ipa-4-4:

  • f0f48ec14f3ff55852393927533ffd253cb5a04b Make kadmin family of functions return the result of ipautil.run
  • e02323c1c3b3c3dadd57d9f1885ec1af046718de Add a basic test suite for kadmin.local interface

Metadata Update from @mbasti:
- Issue assigned to dkupka
- Issue set to the milestone: FreeIPA 4.3.3

Metadata