On Wed, Nov 11, 2009 at 09:55:25AM -0500, Stephen Gallagher wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > On 11/11/2009 09:22 AM, Sumit Bose wrote: > > Hi, > > > > this patch fixes a bug in the procy provider and makes > > proxy_pam_target a mandatory option, because we do not ship a matching > > pam configuration for the old default. > > > > bye, > > Sumit > > > > > > > > _______________________________________________ > > sssd-devel mailing list > > sssd-devel@lists.fedorahosted.org > > https://fedorahosted.org/mailman/listinfo/sssd-devel > > Nack > > The code is still assuming that an unspecified access backend should be > using the ID provider. It's failing to start because of a missing > proxy_pam_target option now. > > As discussed on IRC, defaulting to the ID provider for access control > doesn't make sense to me.
I will address this in a different patch to the data provider backend. This patch only fixes issues found in the proxy provider which are independent of the fallback strategy. bye, Sumit > > > [sssd[be[sgallagh_proxy]]] [load_backend_module] (7): Loading backend > [proxy] with path [/usr/lib64/sssd/libsss_proxy.so]. > [sssd[be[sgallagh_proxy]]] [be_process_init] (9): ID backend target > successfully loaded from provider [proxy]. > [sssd[be[sgallagh_proxy]]] [load_backend_module] (7): Loading backend > [krb5] with path [/usr/lib64/sssd/libsss_krb5.so]. > [sssd[be[sgallagh_proxy]]] [dp_get_options] (6): Option krb5_kdcip has > value vm-094.idm.lab.bos.redhat.com > [sssd[be[sgallagh_proxy]]] [dp_get_options] (6): Option krb5_realm has > value SGALLAGH.EXAMPLE.COM > [sssd[be[sgallagh_proxy]]] [dp_get_options] (6): Option krb5_ccachedir > has value /tmp > [sssd[be[sgallagh_proxy]]] [dp_get_options] (6): Option krb5_ccname_tmpl > has value FILE:%d/krb5cc_%U_XXXXXX > [sssd[be[sgallagh_proxy]]] [dp_get_options] (6): Option > krb5_changepw_principle has value kadmin/changepw > [sssd[be[sgallagh_proxy]]] [dp_get_options] (6): Option > krb5_auth_timeout has value 15 > [sssd[be[sgallagh_proxy]]] [be_process_init] (9): AUTH backend target > successfully loaded from provider [krb5]. > [sssd[be[sgallagh_proxy]]] [load_backend_module] (5): no module name > found in confdb, using [proxy]. > [sssd[be[sgallagh_proxy]]] [load_backend_module] (7): Backend [proxy] > already loaded. > [sssd[be[sgallagh_proxy]]] [sssm_proxy_auth_init] (1): Missing option > proxy_pam_target. > [sssd[be[sgallagh_proxy]]] [load_backend_module] (0): Error (22) in > module (proxy) initialization (sssm_proxy_access_init)! > [sssd[be[sgallagh_proxy]]] [be_process_init] (0): No ACCESS backend > target available. > [sssd[be[sgallagh_proxy]]] [main] (0): Could not initialize backend [22] > > > - -- > Stephen Gallagher > RHCE 804006346421761 > > Delivering value year after year. > Red Hat ranks #1 in value among software vendors. > http://www.redhat.com/promo/vendor/ > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.9 (GNU/Linux) > Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org/ > > iEYEARECAAYFAkr60FcACgkQeiVVYja6o6N9qgCcCAn54rnO27fINxA3QlgECsz3 > QNcAnigGn8aSFmVWuni4PO+TjQSnBvqk > =S9d+ > -----END PGP SIGNATURE----- > _______________________________________________ > sssd-devel mailing list > sssd-devel@lists.fedorahosted.org > https://fedorahosted.org/mailman/listinfo/sssd-devel _______________________________________________ sssd-devel mailing list sssd-devel@lists.fedorahosted.org https://fedorahosted.org/mailman/listinfo/sssd-devel