[Bug 839625] New: Configuring_an_IPA_Client_on_AIX instructs to configure sshd with 'GSSAPITrustDNS' which causes sshd to no longer start

bugzilla at redhat.com bugzilla at redhat.com
Thu Jul 12 13:01:13 UTC 2012


https://bugzilla.redhat.com/show_bug.cgi?id=839625

            Bug ID: 839625
        QA Contact: docs at lists.fedoraproject.org
          Severity: medium
           Version: devel
          Priority: medium
                CC: eric at christensenplace.us, oglesbyzm at gmail.com,
                    stickster at gmail.com
          Assignee: nobody at fedoraproject.org
           Summary: Configuring_an_IPA_Client_on_AIX instructs to
                    configure sshd with 'GSSAPITrustDNS' which causes sshd
                    to no longer start
        Regression: ---
      Story Points: ---
    Classification: Fedora
                OS: Linux
          Reporter: chorn at redhat.com
              Type: Bug
     Documentation: ---
          Hardware: All
        Mount Type: ---
            Status: NEW
         Component: docs-requests
           Product: Fedora Documentation

Description of problem:
http://docs.fedoraproject.org/en-US/Fedora/17/html/FreeIPA_Guide/Configuring_an_IPA_Client_on_AIX.html
instructs to set 'GSSAPITrustDNS no' in /etc/ssh/sshd_config .

Version-Release number of selected component (if applicable):
   current / fedora [15|16|17] instructions

How reproducible:
   always

Steps to Reproduce:
1. access webpage
2. implement change
3. try to start sshd

Actual results:
sshd no longer starts

Expected results:
sshd should start

Additional info:
- GSSAPITrustDNS is a ssh client option
- its not mentioned in the manpage but recognized
-
http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6/html/Identity_Management_Guide/Kerberos_Errors.html
mentions it as client option
- http://freeipa.com/page/ConfiguringAixClients looks like the most current
howto and does not mention the option at all. I think just removing the option
from the webpage is the most simple way to resolve this (recheck whole howto
with an AIX client for bonus)

-- 
You are receiving this mail because:
You are the QA Contact for the bug.


More information about the docs mailing list