Bug 1169241 - AUDIT-0: authselect: review of profiles
AUDIT-0: authselect: review of profiles
Status: RESOLVED INVALID
Classification: openSUSE
Product: openSUSE Tumbleweed
Classification: openSUSE
Component: Security
Current
Other Other
: P5 - None : Normal (vote)
: ---
Assigned To: Sasi Olin
E-mail List
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-04-12 15:58 UTC by Sasi Olin
Modified: 2020-08-12 11:07 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sasi Olin 2020-04-12 15:58:19 UTC
Hi,

Due to continuous work being done with porting FreeIPA to openSUSE Distributions, we have a need to include Authselect in Factory. We want to make sure you don't have any security-related objections to the profiles shipped within it.

https://build.opensuse.org/package/show/home:Pharaoh_Atem:Authselect_SUSE/authselect
Comment 1 Matthias Gerstner 2020-04-14 07:56:01 UTC
Hello and thank you for approaching us.

Do we need us to check out all the available profiles or should we concentrate
on specific ones?
Comment 2 Sasi Olin 2020-04-14 10:38:10 UTC
(In reply to Matthias Gerstner from comment #1)
> Hello and thank you for approaching us.
> 
> Do we need us to check out all the available profiles or should we
> concentrate
> on specific ones?

It seems we only really need sssd profiles for FreeIPA,
Comment 3 Neal Gompa 2020-04-15 00:34:22 UTC
(In reply to Matthias Gerstner from comment #1)
> Hello and thank you for approaching us.
> 
> Do we need us to check out all the available profiles or should we
> concentrate
> on specific ones?

Please review all of them, but the initial priority is the SSSD one, as we need that for FreeIPA and the upcoming openSUSE Accounts platform...

I'd like to get authselect into Factory with as much intact as possible, and ideally if any changes are needed that they could be proposed upstream for both Fedora and openSUSE to benefit.
Comment 4 Neal Gompa 2020-04-15 01:51:54 UTC
(In reply to Stasiek Michalski from comment #0)
> Hi,
> 
> Due to continuous work being done with porting FreeIPA to openSUSE
> Distributions, we have a need to include Authselect in Factory. We want to
> make sure you don't have any security-related objections to the profiles
> shipped within it.
> 
> https://build.opensuse.org/package/show/home:Pharaoh_Atem:Authselect_SUSE/
> authselect

The package has now moved to "security:idm".

https://build.opensuse.org/package/show/security:idm/authselect
Comment 5 Matthias Gerstner 2020-05-04 13:06:33 UTC
I will have a look into this now.
Comment 6 Matthias Gerstner 2020-05-05 13:47:11 UTC
This tool is having some problems with PAM on openSUSE. It operates on
/etc/pam.d/system-auth. But on openSUSE this file is not used. Instead we use
the pam-config utility which creates files like
/etc/pam.d/common-{account,auth,password,session}.

These two tools might conflict with each other regarding the PAM
configuration. Some pam module RPMs for openSUSE also explicitly call
pam-config during installation to add/remove themselves to/from the PAM stack.

You might want to talk about our pam and pam-config maintainers about this and
if a solution can be found.
Comment 7 Matthias Gerstner 2020-05-07 11:28:31 UTC
Reviewing the profiles in detail only partly makes sense. The profiles come
with a bunch of "features" and depending on which features are used a large
number of different combinations is the result.

I can of course look into the base profiles without any features enabled but
they will probably be fine given the simplicity.

For now I'm waiting for you to clear up the conflict I mentioned in comment 6.
Please let me know how you want to proceed with this.
Comment 8 Matthias Gerstner 2020-05-18 11:45:06 UTC
Reassigning to bug creator. Can you please give a statement in which direction
you like to proceed given what I said in comment 6 and comment 7? Thanks.
Comment 9 Sasi Olin 2020-05-18 12:06:27 UTC
We will try to talk with PAM stack maintainers, and see where that leads us
Comment 10 Matthias Gerstner 2020-08-12 11:07:17 UTC
Since there has been no progress for a long time I'm closing this bug as
INVALID. If you can find a way to make the package compatible with SUSE then
feel free to reopen and we will review.