#4905 [RFE] Allow Kerberos authentication for users with certificates on smart cards (pkinit)
Closed: fixed by rcritten. Opened by mkosek.

This requirement has several parts:

  • Support of Smart Cards in SSSD (upstream ticket)
  • API/CLI for configuring the trusted CA certificate in KDC (related - #616)
  • Optionally, also #521 (Add dogtag support to generate KDC certificatesfor Pkinit)
  • Enable PKINIT on clients by default and add respective RPM requirements (krb5-pkinit{,-openssl}) for freeipa-client.

Ticket has been cloned to Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1200767

The current development status of this feature was discussed and it's scope will be limited for the first release. SC authentication will be LDAP-based (details in https://bugzilla.redhat.com/show_bug.cgi?id=854396#c6).

Kerberos authentication or automatic retrieval of user TGT after authentication (pkinit) will be postponed, given the functionality currently requires special certificate extension (id-pkinit-san) in order to properly map certificates and (user) principals. This is not guaranteed with the primary supported cards (CAC), so we would first need to work on extending our Kerberos backend to provide the mapping ourselves.

Metadata Update from @mkosek:
- Issue assigned to someone
- Issue set to the milestone: FreeIPA 4.5

Metadata Update from @pvoborni:
- Custom field on_review adjusted to https://github.com/freeipa/freeipa/pull/575 (was: 0)
- Issue assigned to sbose (was: someone)
- Issue close_status updated to: None

Metadata Update from @mbasti:
- Issue set to the milestone: FreeIPA 4.5.1 (was: FreeIPA 4.5)

master:

  • da880decfedc66f9d0d2734dcb86c23a8866f603 ipa-kdb: add ipadb_fetch_principals_with_extra_filter()
  • c4156041feb9c48598427ad59e43313b9c7327bb IPA certauth plugin
    ipa-4-5:

  • cfaaf4e821338dbc146dd49d3c22978165d2e329 ipa-kdb: add ipadb_fetch_principals_with_extra_filter()

  • 5a1ce1fbaa6c7a85bd1bee2a70b8b22509ede7c7 IPA certauth plugin

master:

  • 2dda1acf44dc96e660e81baadee9c3a54bf05eb0 spec file: bump krb5-devel BuildRequires for certauth

ipa-4-5:

  • 2d246000ef2d715fab464b8ef71fdb3731da127e spec file: bump krb5-devel BuildRequires for certauth

master:

  • 0f42670afa935801c25bc66f733a8d1b90ea5a0b spec file: bump krb5 Requires for certauth fixes

ipa-4-5:

  • ec3a2a6063beb4ec96796b66abb82476a5c7bd0f spec file: bump krb5 Requires for certauth fixes

@mbabinsk can we close this ticket as fixed?

Metadata Update from @mbasti:
- Issue set to the milestone: FreeIPA 4.5.2 (was: FreeIPA 4.5.1)

FreeIPA 4.5.1 has been released, moving to FreeIPA 4.5.2 milestone

Metadata Update from @tkrizek:
- Issue set to the milestone: FreeIPA 4.5.3 (was: FreeIPA 4.5.2)

Metadata Update from @tkrizek:
- Issue set to the milestone: FreeIPA 4.5.4 (was: FreeIPA 4.5.3)

Metadata Update from @tkrizek:
- Issue set to the milestone: FreeIPA 4.5.5 (was: FreeIPA 4.5.4)

Metadata Update from @rcritten:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

Metadata