I had my QA team attempt to reproduce this problem and they were unable to do so. Please examine the process below and let us know if there's anything about your environment that differs here.

Method:
1. Installed sssd-1.0.2-1.el6.x86_64
2. Configured sssd.conf [1].
3. Authenticated as "sssd" user - authentication successful.
4. ldbsearch output is as [2].
5. Authenticated as "sssd2" user - authentication successful.
6. ldbsearch output for sssd2 user is as [3].
7. Upgraded to sssd-1.2.0-12.el6.x86_64.rpm
8. Authenticated as "sssd" user - authentication successful.
9. ldbsearch output is as [4].
10. Authenticated as "sssd2" user - authentication sucessful.
11. ldbsearch output is as [5].

Note:
"sssd" user (1.0.2) -> ccacheFile: FILE:/tmp/krb5cc_1005_mPR8tX
"sssd" user (1.2.0) -> ccacheFile: FILE:/tmp/krb5cc_1005_mPR8tX

"sssd2" user (1.0.2) -> ccacheFile: FILE:/tmp/krb5cc_1006_lKcdta
"sssd2" user (1.2.0) -> ccacheFile: FILE:/tmp/krb5cc_1006_OwAmwW

[1] sssd.conf:
[sssd]
config_file_version = 2
reconnection_retries = 3
sbus_timeout = 30
services = nss, pam
domains = shanks

[nss]
filter_groups = root
filter_users = root
reconnection_retries = 3

[pam]
reconnection_retries = 3

[domain/shanks]
auth_provider = krb5
krb5_kdcip = 10.16.78.20
krb5_realm = EXAMPLE.COM
id_provider = ldap
chpass_provider = ldap
ldap_uri = ldaps://shanksldap.idm.lab.bos.redhat.com
ldap_search_base = dc=example,dc=com
ldap_user_search_base = ou=People,dc=example,dc=com
ldap_group_search_base = ou=Groups,dc=example,dc=com
ldap_tls_reqcert = demand
ldap_tls_cacert = /etc/openldap/cacerts/cacert.asc
cache_credentials = true
enumerate = true
min_id = 0
max_id = 0
debug_level = 9


[2] ldbsearch output for "sssd" user:
# ldbsearch -v -H /var/lib/sss/db/cache_shanks.ldb -b
name=sssd,cn=users,cn=shanks,cn=sysdb
asq: Unable to register control with rootdse!
# record 1
dn: name=sssd,cn=users,cn=shanks,cn=sysdb
createTimestamp: 1275575789
gidNumber: 1005
homeDirectory: /export/sssd
loginShell: /bin/bash
name: sssd
objectClass: user
uidNumber: 1005
originalDN: uid=sssd,ou=People,dc=example,dc=com
originalModifyTimestamp: 20100603114440Z
ccacheFile: FILE:/tmp/krb5cc_1005_mPR8tX
cachedPassword:
$6$sKK.bTY.uqHMRAY8$TJkfifCSy9X9ZW2DZb.ITvuK74RUzKHVzlXUvQL3so
 Ds.ibUQjWu1KbjG2xy/7RcdKfFZYy/RkSEqi..HwfCv1
lastCachedPasswordChange: 1275575823
lastOnlineAuth: 1275575823
initgrExpireTimestamp: 1275577627
lastUpdate: 1275575827
dataExpireTimestamp: 1275577627
distinguishedName: name=sssd,cn=users,cn=shanks,cn=sysdb

[3] ldbsearch output for "sssd2" user:
# ldbsearch -v -H /var/lib/sss/db/cache_shanks.ldb -b
name=sssd2,cn=users,cn=shanks,cn=sysdb
asq: Unable to register control with rootdse!
# record 1
dn: name=sssd2,cn=users,cn=shanks,cn=sysdb
createTimestamp: 1275576380
gidNumber: 1006
homeDirectory: /export/sssd2
loginShell: /bin/bash
name: sssd2
objectClass: user
uidNumber: 1006
originalDN: uid=sssd2,ou=People,dc=example,dc=com
originalModifyTimestamp: 20100603145032Z
ccacheFile: FILE:/tmp/krb5cc_1006_lKcdta
cachedPassword:
$6$76GCXRL.Rcb5yUZ6$JkKVeKYJet7Wr52hiytTtOLvd/1MpTqInJymXZtm5A
 TU/KPc87bjdW9pXK9n6isiNUJsQHZ7yENfVnIfWsS7R/
lastCachedPasswordChange: 1275576384
lastOnlineAuth: 1275576385
initgrExpireTimestamp: 1275578186
lastUpdate: 1275576389
dataExpireTimestamp: 1275578189
distinguishedName: name=sssd2,cn=users,cn=shanks,cn=sysdb


[4] ldbsearch output for "sssd" user after upgrade:
# ldbsearch -v -H /var/lib/sss/db/cache_shanks.ldb -b
name=sssd,cn=users,cn=shanks,cn=sysdbasq: Unable to register control
with rootdse!
# record 1
dn: name=sssd,cn=users,cn=shanks,cn=sysdb
createTimestamp: 1275575789
gidNumber: 1005
homeDirectory: /export/sssd
loginShell: /bin/bash
name: sssd
objectClass: user
uidNumber: 1005
originalDN: uid=sssd,ou=People,dc=example,dc=com
originalModifyTimestamp: 20100603114440Z
ccacheFile: FILE:/tmp/krb5cc_1005_mPR8tX
cachedPassword:
$6$7tWYfYCxnY27Thch$i/RZrPkRBvdJHOC9/T5bma7/6zeIPSVZetr/GPlmED
 8LbIPSe.xK5PBz276wU47vLSojLjwCN8QeV8e1NTfKJ.
lastCachedPasswordChange: 1275576583
failedLoginAttempts: 0
lastOnlineAuth: 1275576583
lastLogin: 1275576583
initgrExpireTimestamp: 1275582064
lastUpdate: 1275576664
dataExpireTimestamp: 1275582064


[5] ldbsearch output for "sssd2" user after upgrade:
# ldbsearch -v -H /var/lib/sss/db/cache_shanks.ldb -b
name=sssd2,cn=users,cn=shanks,cn=sysdbasq: Unable to register control
with rootdse!
# record 1
dn: name=sssd2,cn=users,cn=shanks,cn=sysdb
createTimestamp: 1275576380
gidNumber: 1006
homeDirectory: /export/sssd2
loginShell: /bin/bash
name: sssd2
objectClass: user
uidNumber: 1006
originalDN: uid=sssd2,ou=People,dc=example,dc=com
originalModifyTimestamp: 20100603145032Z
ccacheFile: FILE:/tmp/krb5cc_1006_OwAmwW
cachedPassword:
$6$KHGudnPG7NCQvK6a$KlV2suOLgm.jLLYtMHLfL4ZPdheaZ5VGSABIcNP.5p
 k20yR0VZ.NvX73LlANgf.MAKo3bUANfBv13v9ciLwDi0
lastCachedPasswordChange: 1275576702
failedLoginAttempts: 0
lastOnlineAuth: 1275576702
lastLogin: 1275576702
initgrExpireTimestamp: 1275582103
lastUpdate: 1275576703
dataExpireTimestamp: 1275582103
distinguishedName: name=sssd2,cn=users,cn=shanks,cn=sysdb


--
Stephen Gallagher
RHCE 804006346421761

Delivering value year after year.
Red Hat ranks #1 in value among software vendors.
http://www.redhat.com/promo/vendor/



--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to