Learn more about these different git repos.
Other Git URLs
We need logic in SSSD that would allow the GDM prompter to prompt the user for long-term password and the OTP in different prompts.
Nathaniel suggested to use the krb5 responder callback. Citing from his proposal:
That is, the user name is selected in GDM and SSSD begins the krb5 connection. The responder callback is called. Within this callback, SSSD can see exactly what mechanisms can be used to authenticate the user. No connection to LDAP is needed. This should drive the responses (all within the callback). There is no guarantee that SSSD’s analysis of LDAP will drive the choices actually available in the responder callback.
However, I don’t know how this could be done while preserving the communication protocol between the parent and child processes.
milestone: NEEDS_TRIAGE => SSSD 1.12.1
priority: major => blocker
cc: => nalin
Defer cloning, may be linked with an OTP tracker later.
rhbz: => todo
Ticket has been cloned to Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1115854
rhbz: todo => [https://bugzilla.redhat.com/show_bug.cgi?id=1115854 1115854]
blockedby: => 2404
as discussed on a meeting this week, we are not going to implement the changes in 1.12, but rather in 1.13 together with smart card work.
milestone: SSSD 1.12.1 => SSSD 1.13 beta
mark: => 1
owner: somebody => sbose
status: new => assigned
Ticket has been cloned to Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1200873
rhbz: [https://bugzilla.redhat.com/show_bug.cgi?id=1115854 1115854] => [https://bugzilla.redhat.com/show_bug.cgi?id=1115854 1115854], [https://bugzilla.redhat.com/show_bug.cgi?id=1200873 1200873]
resolution: => fixed
status: assigned => closed
design: => https://fedorahosted.org/sssd/wiki/DesignDocs/PAMConversationForOTP
sensitive: => 0
Metadata Update from @jhrozek:
- Issue assigned to sbose
- Issue marked as depending on: #2404
- Issue set to the milestone: SSSD 1.13.1
to comment on this ticket.