<html><body><div style="font-family: arial, helvetica, sans-serif; font-size: 10pt; color: #000000"><div>I agree and thanks for +1 on the bug.</div><div>On the other hand, the PAM checkbox you talk about is not visible in none of my SW servers.</div><div><br></div><div>/Alex</div><div><br data-mce-bogus="1"></div><hr id="zwchr" data-marker="__DIVIDER__"><div data-marker="__HEADERS__"><b>From: </b>"DiOrio, Max" <Max.DiOrio@ieeeglobalspec.com><br><b>To: </b>spacewalk-list@redhat.com<br><b>Sent: </b>Thursday, March 15, 2018 6:39:19 PM<br><b>Subject: </b>Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication<br></div><br><div data-marker="__QUOTED_TEXT__">



<style><!--

@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}

p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
code
        {mso-style-priority:99;
        font-family:"Courier New";}
pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";}
p.msonormal0, li.msonormal0, div.msonormal0
        {mso-style-name:msonormal;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman",serif;}
span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:"Courier New";}
span.EmailStyle21
        {mso-style-type:personal;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
span.EmailStyle22
        {mso-style-type:personal;
        font-family:"Calibri",sans-serif;
        color:#1F497D;}
span.EmailStyle23
        {mso-style-type:personal;
        font-family:"Calibri",sans-serif;
        color:#1F497D;}
span.EmailStyle24
        {mso-style-type:personal;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
span.EmailStyle25
        {mso-style-type:personal;
        font-family:"Calibri",sans-serif;
        color:#1F497D;}
span.EmailStyle26
        {mso-style-type:personal;
        font-family:"Calibri",sans-serif;
        color:#1F497D;}
span.EmailStyle27
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style>


<div class="WordSection1">
<p class="MsoNormal"><a name="_MailEndCompose"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">It seems like it would be trivial to add quick logic that if the user creation is coming from PAM, to automatically “check the box” for Use PAM in the database.  Manually having to check
 the box every time a new user logs in in a pain, and it resolves the issue of being able to use client side tools such as ‘spacewalk-channel’.</span></a></p>
<p class="MsoNormal"><span style="mso-bookmark: _MailEndCompose;" data-mce-style="mso-bookmark: _MailEndCompose;"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span></span></p>
<p class="MsoNormal"><span style="mso-bookmark: _MailEndCompose;" data-mce-style="mso-bookmark: _MailEndCompose;"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">I did add my comment to the bug report.  Thanks for the help Alex!</span></span></p>
<p class="MsoNormal"><span style="mso-bookmark: _MailEndCompose;" data-mce-style="mso-bookmark: _MailEndCompose;"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span></span></p>
<div>
<p class="MsoNormal"><span style="mso-bookmark: _MailEndCompose;" data-mce-style="mso-bookmark: _MailEndCompose;"><b><span style="font-size: 9.5pt; font-family: 'Arial',sans-serif; color: #0066a1;" data-mce-style="font-size: 9.5pt; font-family: 'Arial',sans-serif; color: #0066a1;">Max DiOrio</span></b></span></p>
<p class="MsoNormal" style="line-height: 115%;" data-mce-style="line-height: 115%;"><span style="mso-bookmark: _MailEndCompose;" data-mce-style="mso-bookmark: _MailEndCompose;"><span style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: #1f497d;" data-mce-style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: #1f497d;">Global Systems Administrator</span></span></p>
</div>
<p class="MsoNormal"><span style="mso-bookmark: _MailEndCompose;" data-mce-style="mso-bookmark: _MailEndCompose;"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span></span></p>
<span style="mso-bookmark: _MailEndCompose;" data-mce-style="mso-bookmark: _MailEndCompose;"></span>
<div>
<div style="border: none; border-top: solid #E1E1E1 1.0pt; padding: 3.0pt 0in 0in 0in;" data-mce-style="border: none; border-top: solid #E1E1E1 1.0pt; padding: 3.0pt 0in 0in 0in;">
<p class="MsoNormal"><b>From:</b> spacewalk-list-bounces@redhat.com <spacewalk-list-bounces@redhat.com>
<b>On Behalf Of </b>Alexandru Raceanu<br>
<b>Sent:</b> Thursday, March 15, 2018 3:40 AM<br>
<b>To:</b> spacewalk-list@redhat.com<br>
<b>Subject:</b> Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication</p>
</div>
</div>
<p class="MsoNormal"> </p>
<div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">Well... That part doesn't work at the moment as far as I can see and never managed to get it working on SW 2.5/2.6/2.7.</span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">I've already opened a bug report over 1 year ago ( <a href="https://bugzilla.redhat.com/show_bug.cgi?id=1382974" target="_blank">https://bugzilla.redhat.com/show_bug.cgi?id=1382974</a>
 )</span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;"> </span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">Feel free to add a +1 to that one.</span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;"> </span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">If anyone else has any input on this part, feel free to comment, i'm also interested in fixing this.</span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;"> </span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">/Alex</span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;"> </span></p>
</div>
<div class="MsoNormal" align="center" style="text-align: center;" data-mce-style="text-align: center;"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">
<hr size="2" width="100%" align="center" id="zwchr">
</span></div>
<div>
<p class="MsoNormal"><b><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">From:
</span></b><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">"DiOrio, Max" <<a href="mailto:Max.DiOrio@ieeeglobalspec.com" target="_blank">Max.DiOrio@ieeeglobalspec.com</a>><br>
<b>To: </b><a href="mailto:spacewalk-list@redhat.com" target="_blank">spacewalk-list@redhat.com</a><br>
<b>Sent: </b>Wednesday, March 14, 2018 9:52:15 PM<br>
<b>Subject: </b>Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication</span></p>
</div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;"> </span></p>
<div>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">Sorry – one more issue I’m running into.  Looks like anything that communicates via XMLPRC can’t authenticate. 
</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"># spacewalk-channel --add -c microsoft_rhel7 -u mdiorio -p
</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">Error validating data at server:</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">Error Message:</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">    Invalid username/password combination</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">Error Class Code: 2</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">Error Class Info: Invalid username and password combination.</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">Explanation:</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">     An error has occurred while processing your request. If this problem</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">     persists please enter a bug report at bugzilla.redhat.com.</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">     If you choose to submit the bug report, please be sure to include</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">     details of what you were trying to do when this error occurred and</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">     details on how to reproduce this problem.</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">In the rhn_server_xmlrpc.log, I see the request, but no errors:</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal" style="text-indent: .5in;" data-mce-style="text-indent: .5in;"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">xmlrpc/up2date.subscribeChannels(1000010030, ['microsoft_rhel7'])</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">In ssl_request_log:</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">                10.85.164.46 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384 "POST /XMLRPC HTTP/1.1" 737</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">I can’t find anything specific in any of the event logs as to why it’s failing. 
</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<div>
<p class="MsoNormal"><b><span style="font-size: 9.5pt; font-family: 'Arial',sans-serif; color: #0066a1;" data-mce-style="font-size: 9.5pt; font-family: 'Arial',sans-serif; color: #0066a1;">Max DiOrio</span></b><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal" style="line-height: 115%;" data-mce-style="line-height: 115%;"><span style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: #1f497d;" data-mce-style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: #1f497d;">Global Systems Administrator</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<div>
<div style="border: none; border-top: solid #E1E1E1 1.0pt; padding: 3.0pt 0in 0in 0in;" data-mce-style="border: none; border-top: solid #E1E1E1 1.0pt; padding: 3.0pt 0in 0in 0in;">
<p class="MsoNormal"><b><span style="color: black;" data-mce-style="color: black;">From:</span></b><span style="color: black;" data-mce-style="color: black;">
<a href="mailto:spacewalk-list-bounces@redhat.com" target="_blank">spacewalk-list-bounces@redhat.com</a> [<a href="mailto:spacewalk-list-bounces@redhat.com" target="_blank">mailto:spacewalk-list-bounces@redhat.com</a>]
<b>On Behalf Of </b>DiOrio, Max<br>
<b>Sent:</b> Tuesday, March 13, 2018 2:35 PM<br>
<b>To:</b> <a href="mailto:spacewalk-list@redhat.com" target="_blank">spacewalk-list@redhat.com</a><br>
<b>Subject:</b> Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication</span></p>
</div>
</div>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;"> </span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">Got it!</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">Had to uncomment the following line in lookup_identity.conf</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Courier New'; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Courier New'; color: black;"># LookupUserGroupsIter AJP_REMOTE_USER_GROUP</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">Seems to work perfectly now!  Now to document all this just in case!</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">Thanks for the help.</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<div>
<p class="MsoNormal"><b><span style="font-size: 9.5pt; font-family: 'Arial',sans-serif; color: #0066a1;" data-mce-style="font-size: 9.5pt; font-family: 'Arial',sans-serif; color: #0066a1;">Max DiOrio</span></b><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal" style="line-height: 115%;" data-mce-style="line-height: 115%;"><span style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: #1f497d;" data-mce-style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: #1f497d;">Global Systems Administrator</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<div>
<div style="border: none; border-top: solid #E1E1E1 1.0pt; padding: 3.0pt 0in 0in 0in;" data-mce-style="border: none; border-top: solid #E1E1E1 1.0pt; padding: 3.0pt 0in 0in 0in;">
<p class="MsoNormal"><b><span style="color: black;" data-mce-style="color: black;">From:</span></b><span style="color: black;" data-mce-style="color: black;">
<a href="mailto:spacewalk-list-bounces@redhat.com" target="_blank">spacewalk-list-bounces@redhat.com</a> [<a href="mailto:spacewalk-list-bounces@redhat.com" target="_blank">mailto:spacewalk-list-bounces@redhat.com</a>]
<b>On Behalf Of </b>DiOrio, Max<br>
<b>Sent:</b> Tuesday, March 13, 2018 1:55 PM<br>
<b>To:</b> <a href="mailto:spacewalk-list@redhat.com" target="_blank">spacewalk-list@redhat.com</a><br>
<b>Subject:</b> Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication</span></p>
</div>
</div>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;"> </span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">Thanks Alex – I’m almost there!</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">I can now successfully log into Spacewalk as a user authenticating with SSSD and Group Policy.  Needed to add a few more pieces to get it to work properly – it was doing the authentication but not the authorization,
 and wasn’t passing large Kerberos tokens.</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">It seems my External Authentication Group Role Mapping isn’t working though.  I have created a new group “spacewalkadmins” in AD and added the users to it.  I can id the username and see that the user is a member
 of the group.   I added the group name to the Spacewalk External Authentication Group Role Mapping, but the mapping is not happening.  The user is getting added with no role mapping permissions.</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">Any idea where I can see the logs for what is happening and why it may not be mapping?</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">Thanks!  </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<div>
<p class="MsoNormal"><b><span style="font-size: 9.5pt; font-family: 'Arial',sans-serif; color: #0066a1;" data-mce-style="font-size: 9.5pt; font-family: 'Arial',sans-serif; color: #0066a1;">Max DiOrio</span></b><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal" style="line-height: 115%;" data-mce-style="line-height: 115%;"><span style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: #1f497d;" data-mce-style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: #1f497d;">Global Systems Administrator</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<div>
<div style="border: none; border-top: solid #E1E1E1 1.0pt; padding: 3.0pt 0in 0in 0in;" data-mce-style="border: none; border-top: solid #E1E1E1 1.0pt; padding: 3.0pt 0in 0in 0in;">
<p class="MsoNormal"><b><span style="color: black;" data-mce-style="color: black;">From:</span></b><span style="color: black;" data-mce-style="color: black;">
<a href="mailto:spacewalk-list-bounces@redhat.com" target="_blank">spacewalk-list-bounces@redhat.com</a> [<a href="mailto:spacewalk-list-bounces@redhat.com" target="_blank">mailto:spacewalk-list-bounces@redhat.com</a>]
<b>On Behalf Of </b>Alexandru Raceanu<br>
<b>Sent:</b> Monday, March 12, 2018 2:58 PM<br>
<b>To:</b> <a href="mailto:spacewalk-list@redhat.com" target="_blank">spacewalk-list@redhat.com</a><br>
<b>Subject:</b> Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication</span></p>
</div>
</div>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;"> </span></p>
<div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">Try to go trough the SW/FreeIPA documentation (<a href="https://github.com/spacewalkproject/spacewalk/wiki/SpacewalkAndIPA" target="_blank">https://github.com/spacewalkproject/spacewalk/wiki/SpacewalkAndIPA</a>)<br>
DON'T COPY PASTE, read, understand and skip the parts of ipa installation and config as you already have sssd up and running so that should be sufficient.</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">Take a backup before you mess around with you SW deployment so I won't feel bad about the tips!</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;"><br>
As far as the channel related stuff, after you have the external auth working for rhn admins, you should be able to map another group for dev's with specific permissions (subscribe/unsubscribe systems to software channels)<br>
<br>
That's at least how the theory would be, personally I would prefer to add all development required software channels to the whole development env/machines, and they can install whatever they want from that channels.</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">It will save you the hassle of educating users on how to use spacewalk or other time consuming questions.</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">/Alex</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<div class="MsoNormal" align="center" style="text-align: center;" data-mce-style="text-align: center;"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">
<hr size="2" width="100%" align="center">
</span></div>
<div>
<p class="MsoNormal"><b><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">From:
</span></b><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">"DiOrio, Max" <<a href="mailto:Max.DiOrio@ieeeglobalspec.com" target="_blank">Max.DiOrio@ieeeglobalspec.com</a>><br>
<b>To: </b><a href="mailto:spacewalk-list@redhat.com" target="_blank">spacewalk-list@redhat.com</a><br>
<b>Sent: </b>Monday, March 12, 2018 7:44:07 PM<br>
<b>Subject: </b>Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<div>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">SW 2.7 on RHEL 7.4</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">The HTTPD conf files are either commented out, or in the case of auth_kerb.conf, empty.  This is a completely out of the box setup and the only documentation I’ve been able to find on this on RH’s portal mentions
 just the config changes I made.  Nothing to do with the files you mentioned.</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">Is there a better how-to to describe the full changes that need to take place to enable this?</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">As far as role map, I only want end users to be able to subscribe to additional software channels that we don’t push by default.  For example, we don’t have Microsoft’s channel in our base activation key, but
 would like to give our developers an opportunity to install software from it without admin intervention.</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;">It appears that doing spacewalk-channel –add –c microsoft_rhel7    prompts for a username and password so they are unable to add the channel.</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<div>
<p class="MsoNormal"><b><span style="font-size: 9.5pt; font-family: 'Arial',sans-serif; color: #0066a1;" data-mce-style="font-size: 9.5pt; font-family: 'Arial',sans-serif; color: #0066a1;">Max DiOrio</span></b><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal" style="line-height: 115%;" data-mce-style="line-height: 115%;"><span style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: #1f497d;" data-mce-style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: #1f497d;">Global Systems Administrator</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<p class="MsoNormal"><span style="color: #1f497d;" data-mce-style="color: #1f497d;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<div>
<div style="border: none; border-top: solid #E1E1E1 1.0pt; padding: 3.0pt 0in 0in 0in;" data-mce-style="border: none; border-top: solid #E1E1E1 1.0pt; padding: 3.0pt 0in 0in 0in;">
<p class="MsoNormal"><b><span style="color: black;" data-mce-style="color: black;">From:</span></b><span style="color: black;" data-mce-style="color: black;">
<a href="mailto:spacewalk-list-bounces@redhat.com" target="_blank">spacewalk-list-bounces@redhat.com</a> [<a href="mailto:spacewalk-list-bounces@redhat.com" target="_blank">mailto:spacewalk-list-bounces@redhat.com</a>]
<b>On Behalf Of </b>Alexandru Raceanu<br>
<b>Sent:</b> Monday, March 12, 2018 2:08 PM<br>
<b>To:</b> <a href="mailto:spacewalk-list@redhat.com" target="_blank">spacewalk-list@redhat.com</a><br>
<b>Subject:</b> Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication</span></p>
</div>
</div>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;"> </span></p>
<div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">Spacewalk version and OS please...</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">Also log entries except the tomcat would be helpful.</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">What's the content of following:<br>
/etc/httpd/conf.d/intercept_form_submit.conf</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black; background: white;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black; background: white;">/etc/httpd/conf.d/</span><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">authnz_pam.conf</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black; background: white;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black; background: white;">/etc/httpd/conf.d/</span><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">auth_kerb.conf</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">I don't think that you need to create the user if you do role map for external authenticated users ( Admin -> Users -> External Authentication -> Group Role Mapping
 )</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;"><br>
<br>
/Alex</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<div class="MsoNormal" align="center" style="text-align: center;" data-mce-style="text-align: center;"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">
<hr size="2" width="100%" align="center">
</span></div>
<div>
<p class="MsoNormal"><b><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">From:
</span></b><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;">"DiOrio, Max" <<a href="mailto:Max.DiOrio@ieeeglobalspec.com" target="_blank">Max.DiOrio@ieeeglobalspec.com</a>><br>
<b>To: </b><a href="mailto:spacewalk-list@redhat.com" target="_blank">spacewalk-list@redhat.com</a><br>
<b>Sent: </b>Monday, March 12, 2018 4:52:21 PM<br>
<b>Subject: </b>[Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication</span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;"> </span><span style="color: black;" data-mce-style="color: black;"></span></p>
<div>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;">Hi!</span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;"> </span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;">I’m looking to potentially use SSSD and Active Directory to authenticate our users to Spacewalk.  The Spacewalk server is already on the domain and we authenticate just fine via SSH using AD.</span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;"> </span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;">I added the following to the rhn.conf file:</span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;">pam_auth_service = spacewalk-satellite</span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;"> </span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;">Created the spacewalk-satellite pam.d file:</span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;">#%PAM-1.0</span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;"> </span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;">auth    required        pam_env.so</span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;">auth    sufficient      pam_sss.so no_user_check</span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;">auth    required        pam_deny.so</span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;"> </span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;">account required        pam_sss.so no_user_check</span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;"> </span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;">Restarted spacewalk.   Created a user mdiorio in the GUI and checked the box to use PAM.</span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;"> </span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;">But get the following error when I go to log in.</span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;"> </span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;">Mar 12 11:51:21 la-1pspacewalk server: 2018-03-12 11:51:21,304 [ajp-bio-0:0:0:0:0:0:0:1-8009-exec-4] WARN  com.redhat.rhn.domain.user.legacy.UserImpl - PAM login for user User mdiorio (id 2, org_id 1) failed with
 error Permission denied.</span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;">Mar 12 11:51:23 la-1pspacewalk server: 2018-03-12 11:51:23,304 [ajp-bio-0:0:0:0:0:0:0:1-8009-exec-4] INFO  com.redhat.rhn.frontend.action.LoginAction - LOCAL AUTH FAILURE: [mdiorio]</span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;"> </span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;">I can kinit my account on the server without a problem.</span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;"> </span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;">Not sure what I’m missing.   Thanks!</span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;"> </span></p>
<p class="MsoNormal"><b><span style="font-size: 9.5pt; font-family: 'Arial',sans-serif; color: #0066a1;" data-mce-style="font-size: 9.5pt; font-family: 'Arial',sans-serif; color: #0066a1;">Max DiOrio</span></b><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal" style="line-height: 115%;" data-mce-style="line-height: 115%;"><span style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: black;">Global Systems Administrator</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal" style="line-height: 115%;" data-mce-style="line-height: 115%;"><span style="color: black;" data-mce-style="color: black;"><img border="0" width="175" height="46" style="width: 1.8229in; height: .4791in;" id="Picture_x0020_5" src="cid:image001.jpg@01D3BC63.0374B240" alt="cid:image002.jpg@01D26A5C.D5C0BF00" data-mce-style="width: 1.8229in; height: .4791in;"></span></p>
<p class="MsoNormal" style="line-height: 115%;" data-mce-style="line-height: 115%;"><span style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: black;">201 Fuller Road, Suite 202</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal" style="line-height: 115%;" data-mce-style="line-height: 115%;"><span style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: black;">Albany, NY 12203-3621</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal" style="line-height: 115%;" data-mce-style="line-height: 115%;"><span style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: black;">Phone: +518-238-6516 | Mobile: +518-944-5289</span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal" style="margin-bottom: 12.0pt; line-height: 115%;" data-mce-style="margin-bottom: 12.0pt; line-height: 115%;"><span style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 9.5pt; line-height: 115%; font-family: 'Arial',sans-serif; color: black;"><a href="mailto:max.diorio@ieeeglobalspec.com" target="_blank"><span style="color: blue;" data-mce-style="color: blue;">max.diorio@ieeeglobalspec.com</span></a></span><span style="color: black;" data-mce-style="color: black;"></span></p>
<p class="MsoNormal"><span style="color: black;" data-mce-style="color: black;"> </span></p>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;"><br>
_______________________________________________<br>
Spacewalk-list mailing list<br>
<a href="mailto:Spacewalk-list@redhat.com" target="_blank">Spacewalk-list@redhat.com</a><br>
<a href="https://www.redhat.com/mailman/listinfo/spacewalk-list" target="_blank">https://www.redhat.com/mailman/listinfo/spacewalk-list</a></span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
</div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;"><br>
_______________________________________________<br>
Spacewalk-list mailing list<br>
<a href="mailto:Spacewalk-list@redhat.com" target="_blank">Spacewalk-list@redhat.com</a><br>
<a href="https://www.redhat.com/mailman/listinfo/spacewalk-list" target="_blank">https://www.redhat.com/mailman/listinfo/spacewalk-list</a></span><span style="color: black;" data-mce-style="color: black;"></span></p>
</div>
</div>
<p class="MsoNormal"><span style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;" data-mce-style="font-size: 10.0pt; font-family: 'Arial',sans-serif; color: black;"><br>
_______________________________________________<br>
Spacewalk-list mailing list<br>
<a href="mailto:Spacewalk-list@redhat.com" target="_blank">Spacewalk-list@redhat.com</a><br>
<a href="https://www.redhat.com/mailman/listinfo/spacewalk-list" target="_blank">https://www.redhat.com/mailman/listinfo/spacewalk-list</a></span></p>
</div>
</div>
</div>


<br>_______________________________________________<br>Spacewalk-list mailing list<br>Spacewalk-list@redhat.com<br>https://www.redhat.com/mailman/listinfo/spacewalk-list<br></div></div></body></html>