LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-12-2020, 10:15 AM   #1
jergau
LQ Newbie
 
Registered: Sep 2020
Posts: 1

Rep: Reputation: Disabled
Cached credentials not working after sssd restarts


We are trying to set sssd on CentOS 8 computers to cache the user credentials with Kerberos authentication. The issue that it works fine until we restart the sssd service, after that login with cached credentials stops working. It looks like restarting the service clears out the cache so the credentials are not there (or not used) anymore and we need to reconnect to the kerberos server to login again. This is a big problem since rebooting the computer actually restarts sssd so every time someone brings his laptop at home he cannot login anymore (unless he doesn't turn it off during the trip).

I am pretty sure my sssd.conf includes everything I need for the caching:

id_provider = files
auth_provider = krb5
cache_credential = True
krb5_store_password_if_offline = True


For the krb5.conf I tried to not define any default_ccache_name, tried with FILE:/tmp/krb5cc_%{uid} and with keyring as well but none of them seem to have any effect (I think sssd caches the credentials in it's own database so Kerberos caching configuration doesn't matter but maybe I am wrong).

Also if I set any values different than 0 for offline_credentials_expiration in the pam section of the sssd.conf, for example:

[pam]
offline_credentials_expiration = 60


the caching stops working completely (no need to restart or reboot it just doesn't work at all). Maybe this is a separated problem but it may also be related so I mention it just in case. But for the moment my priority is to solve the restarting problem.

Any idea why sssd cannot keep the cached credentials when it restarts?

Thank you!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] sssd: Benign local domain sssd.conf needed boxyzzy Linux - Server 1 10-06-2016 01:31 PM
Problem accessing samba share from Windows 7 using locally cached credentials MooseislooseJH Linux - Security 12 05-20-2014 09:35 PM
Delete Samba cached credentials on Win XP / Win 7 vikas027 Linux - Software 3 08-04-2013 08:26 AM
gpg-agent: cached credentials are secure? hydraMax Linux - Security 1 11-29-2011 03:07 AM
Computer restarts after syslogd restarts birdseye Linux - General 2 03-05-2006 04:27 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:03 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration