Closed Bug 1673437 Opened 5 years ago Closed 3 years ago

Firefox flatpak unable to access kerberos ticket

Categories

(Core :: Widget: Gtk, defect, P3)

Firefox 82
defect

Tracking

()

RESOLVED FIXED
114 Branch
Tracking Status
firefox114 --- fixed

People

(Reporter: jan, Assigned: stransky)

References

(Blocks 1 open bug)

Details

Attachments

(1 file)

User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:82.0) Gecko/20100101 Firefox/82.0

Steps to reproduce:

  1. Obtain kerberos ticket via kinit

  2. Go to about:config and set network.negotiate-auth.trusted-uris to domain

  3. navigate to URL behind kerberos auth

Actual results:

Firefox does not authenticate using kerberos ticket (no access from inside flatpak sandbox).

Expected results:

Firefox flatpak should have access to kerberos tickets outside of the sandbox.

$ flatpak info org.mozilla.firefox

Firefox - Mozilla Firefox Web Browser

      ID: org.mozilla.firefox
     Ref: app/org.mozilla.firefox/x86_64/stable
    Arch: x86_64
  Branch: stable
 Version: 82.0
 License: MPL-2.0
  Origin: flathub

Collection: org.flathub.Stable
Installation: system
Installed: 215,3 MB
Runtime: org.freedesktop.Platform/x86_64/19.08
Sdk: org.freedesktop.Sdk/x86_64/19.08

  Commit: a0b41cf81fcc1766da9bf6a96f4514c81a35a0eeb5edc958e853607ed4687c28
  Parent: 7226dd95603790172b8a67263b9c0754d4bc692149d6f1d54ddff1a2a9537842
 Subject: Export org.mozilla.firefox
    Date: 2020-10-20 12:47:44 +0000

Here is bug where the same issue was addressed in Fedora's flatpak of Firefox: https://bugzilla.redhat.com/show_bug.cgi?id=1699235

Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:82.0) Gecko/20100101 Firefox/82.0

Hi,

I will move this over to a component so developers can take a look over it. If this is not the correct component please feel free to change it to an appropriate one.

Thanks for the report.

Component: Untriaged → Widget: Gtk
Product: Firefox → Core
Blocks: flatpak
Priority: -- → P3

Hi, with /etc/krb5.conf.d accessible to flatpak and cache set to KCM:
flatpak run --filesystem=/run/.heim_org.h5l.kcm-socket --filesystem=/etc/krb5.conf:ro $(for file in /etc/krb5.conf.d/* ; do echo --filesystem=${file}:ro; done) --env="KRB5CCNAME=KCM:" --env=NSPR_LOG_MODULES=timestamp,negotiateauth:5 org.mozilla.firefox

I got from this error:
2020-11-27 17:40:40.883571 UTC - [Parent 2: Main Thread]: D/negotiateauth nsHttpNegotiateAuth::ChallengeReceived URI blocked

To this error:
2020-11-28 09:27:35.708738 UTC - [Parent 2: Main Thread]: D/negotiateauth service = <URI>
2020-11-28 09:27:35.708783 UTC - [Parent 2: Main Thread]: D/negotiateauth using negotiate-gss
2020-11-28 09:27:35.708806 UTC - [Parent 2: Main Thread]: D/negotiateauth entering nsAuthGSSAPI::nsAuthGSSAPI()
2020-11-28 09:27:35.709342 UTC - [Parent 2: Main Thread]: D/negotiateauth Fail to load gssapi library
2020-11-28 09:27:35.709362 UTC - [Parent 2: Main Thread]: D/negotiateauth entering nsAuthGSSAPI::Init()

This didn't change when I added libs from krb5-libs package and tried to use them as network.negotiate-auth.gsslib, the error was then one line longer:
20-11-28 09:27:13.643067 UTC - [Parent 2: Main Thread]: D/negotiateauth service = <URI>
2020-11-28 09:27:13.643109 UTC - [Parent 2: Main Thread]: D/negotiateauth using negotiate-gss
2020-11-28 09:27:13.643121 UTC - [Parent 2: Main Thread]: D/negotiateauth entering nsAuthGSSAPI::nsAuthGSSAPI()
2020-11-28 09:27:13.643142 UTC - [Parent 2: Main Thread]: D/negotiateauth Attempting to load user specified library [/usr/lib64/libkrb5.so.3.3]
2020-11-28 09:27:13.643265 UTC - [Parent 2: Main Thread]: D/negotiateauth Fail to load gssapi library
2020-11-28 09:27:13.643281 UTC - [Parent 2: Main Thread]: D/negotiateauth entering nsAuthGSSAPI::Init()

If this issue had workaround with command line and about:config magic, it would be great!

I have the same problem with Flathub instance. But version from Fedora flatpak repository works fine.

There's a missing libgssapi.so in the runtime. I'm not sure from where it should get it ATM. Also to allow using gssapi you need to set the network.negotiate-auth.trusted-uris to the https:// (or what suits you better)

Unfortunately the kerberos has been removed from the freedesktop runtime: https://gitlab.com/freedesktop-sdk/freedesktop-sdk/-/commit/7a4ee266ee42852e73e5ddcadbcdd9a64759bedc so we need to find a way how to put it back. By trying to revert the change in the freedesktop or using an Extension: https://github.com/flatpak/flatpak/wiki/Extensions

(In reply to Jan Horak [:jhorak] from comment #6)

Unfortunately the kerberos has been removed from the freedesktop runtime: https://gitlab.com/freedesktop-sdk/freedesktop-sdk/-/commit/7a4ee266ee42852e73e5ddcadbcdd9a64759bedc so we need to find a way how to put it back. By trying to revert the change in the freedesktop or using an Extension: https://github.com/flatpak/flatpak/wiki/Extensions

The easiest way is to add it in baseapp[1] where every other FF optional dependency is stored.

[1] https://github.com/flathub/org.mozilla.firefox.BaseApp

Unfortunately the fix does not seem to work

+++ Firefox via flathub

$ flatpak info org.mozilla.firefox

Firefox - Mozilla Firefox Web Browser

          ID: org.mozilla.firefox
         Ref: app/org.mozilla.firefox/x86_64/stable
        Arch: x86_64
      Branch: stable
     Version: 91.0.2
     License: MPL-2.0
      Origin: flathub
  Collection: org.flathub.Stable
Installation: system
   Installed: 238.3 MB
     Runtime: org.freedesktop.Platform/x86_64/20.08
         Sdk: org.freedesktop.Sdk/x86_64/20.08

      Commit: 8729eb0d73ae187b98cbf5ffb381dc25b6d7719f159a286a671b2ec387b60312
      Parent: d79e470d18fa27270d2055723b7509876c6878158d38aef35f9fd296f6188806
     Subject: Export org.mozilla.firefox
        Date: 2021-08-24 12:47:04 +0000
$ cat /var/lib/flatpak/app/org.mozilla.firefox/x86_64/stable/active/files/etc/krb5.conf
[libdefaults]
    dns_lookup_realm = false
    ticket_lifetime = 24h
    renew_lifetime = 7d
    forwardable = true
    rdns = false
    pkinit_anchors = FILE:/etc/ssl/certs/ca-certificates.crt
    spake_preauth_groups = edwards25519
    default_ccache_name = KCM:

+++ Kerberos info

$ klist
Ticket cache: KCM:1000
Default principal: heytherethisisfake@IPA.REDHAT.COM

Valid starting     Expires            Service principal
24/08/21 18:25:04  25/08/21 04:25:04  krbtgt/IPA.REDHAT.COM@IPA.REDHAT.COM
	renew until 25/08/21 18:25:02
24/08/21 18:25:08  25/08/21 04:25:04  HTTP/heytherethisisfake.redhat.com@
	renew until 25/08/21 18:25:02
	Ticket server: HTTP/heytherethisisfake.redhat.com@IPA.REDHAT.COM

+++ Firefox via fedora (this one does work)

$ flatpak info org.mozilla.Firefox

Firefox - Web Browser

          ID: org.mozilla.Firefox
         Ref: app/org.mozilla.Firefox/x86_64/stable
        Arch: x86_64
      Branch: stable
     Version: 90.0.2
     License: GPL-3.0+
      Origin: fedora
  Collection: 
Installation: system
   Installed: 280.7 MB
     Runtime: org.fedoraproject.Platform/x86_64/f34
         Sdk: org.fedoraproject.Sdk/x86_64/f34

      Commit: 17e7729c765920d15d46ef4c9c5075d5a9df6c2010a8177aa53806c927ae3d9b
     Subject: Export org.mozilla.Firefox
        Date: 2021-07-23 15:12:42 +0000
      Alt-id: b765534e3794397ea480a65d1e961eff32af141d7e3a81d80f14769e4ef4bac1
$ cat /var/lib/flatpak/runtime/org.fedoraproject.Platform/x86_64/f34/active/files/etc/krb5.conf
# To opt out of the system crypto-policies configuration of krb5, remove the
# symlink at /etc/krb5.conf.d/crypto-policies which will not be recreated.
includedir /etc/krb5.conf.d/

[logging]
    default = FILE:/var/log/krb5libs.log
    kdc = FILE:/var/log/krb5kdc.log
    admin_server = FILE:/var/log/kadmind.log

[libdefaults]
    dns_lookup_realm = false
    ticket_lifetime = 24h
    renew_lifetime = 7d
    forwardable = true
    rdns = false
    pkinit_anchors = FILE:/etc/pki/tls/certs/ca-bundle.crt
    spake_preauth_groups = edwards25519
    dns_canonicalize_hostname = fallback
    qualify_shortname = ""
#    default_realm = EXAMPLE.COM
    default_ccache_name = KEYRING:persistent:%{uid}

[realms]
# EXAMPLE.COM = {
#     kdc = kerberos.example.com
#     admin_server = kerberos.example.com
# }

[domain_realm]
# .example.com = EXAMPLE.COM
# example.com = EXAMPLE.COM

I confirm the same problem today with flathub firefox. Installing directly from the archlinux standard repository, without sandboxing, works fine with my kerberos tokens.

For me Kerberos works as excepted on Debian 11 (Bullseye) with the latest org.mozilla.firefox flatpak and the config given by David Jaša. This is what I did:

  1. Install package sssd-kcm

  2. Change Kerberos credential cache to KCM (already the default on Fedora?), e.g. with

export KRB5CCNAME=KCM:
  1. Get a Kerberos ticket with kinit on the host (not within the flatpak)

  2. Test Kerberos configuration in Firefox flatpak

flatpak run --command=bash --filesystem=/run/.heim_org.h5l.kcm-socket --filesystem=/etc/krb5.conf:ro --env="KRB5CCNAME=KCM:" org.mozilla.firefox
# run within firefox flatpak it should print the kerberos identities
klist
  1. Allow Firefox's flatpak to permanently access the KCM socket and Kerberos configuration
flatpak override --user --filesystem=/run/.heim_org.h5l.kcm-socket --filesystem=/etc/krb5.conf:ro --env="KRB5CCNAME=KCM:" org.mozilla.firefox
  1. Run Firefox flatpak and follow the steps to configure Firefox for GSSAPI, e.g. adding your domain to network.negotiate-auth.trusted-uris in about:config

When using a different Kerberos config file (instead of /etc/krb5.conf), then make sure to grant access to this file to flatpak (flatpak override --filesystem ... org.mozilla.firefox) and to set KRB5_CONFIG (flatpak override --env ... org.mozilla.firefox).

I've just tried with the current version of flathub Firefox on Fedora 37 and the only missing bit now it to expose the kerberos socket to the VM. A permanent setting can be using by an override:

# flatpak override --filesystem=/run/.heim_org.h5l.kcm-socket org.mozilla.firefox

I didn't have to add any other override (neither for /etc/krb5.conf nor for any KRB* environment variable). Given it's such a little change, I dared to open a PR for it. :)

Assignee: nobody → stransky
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true

(In reply to David Jaša from comment #12)

I've just tried with the current version of flathub Firefox on Fedora 37 and the only missing bit now it to expose the kerberos socket to the VM. A permanent setting can be using by an override:

# flatpak override --filesystem=/run/.heim_org.h5l.kcm-socket org.mozilla.firefox

I didn't have to add any other override (neither for /etc/krb5.conf nor for any KRB* environment variable). Given it's such a little change, I dared to open a PR for it. :)

So. The exposure of KCM socket is still less-then-ideal solution, it depends on krb5 assumptions within flatpak matching how is kerberos actually configured on the host system. gssproxy is the project that can provide kerberos stuff to the containers without a need to expose configuration or sockets from host system, it's available in flatpak since last year however it seems that we'd need to jump through some hoops if the situation is the same as last year. Luckily, these changes are stuff for flathub manifest so it's more accessible to contributors who don't use Mozilla's instance of mercurial regularly.

The gssproxy feature requires at least flatpak 14.x (latest Ubuntu LTS 22.04 has 12.x) plus relevant change must be available on host as well. This is some prospect for few years from now, currently adding filesystem permission is more reliable.

Pushed by stransky@redhat.com: https://hg.mozilla.org/integration/autoland/rev/9bf2dd6d7b48 [Flatpak] Enable access to kerberos r=jhorak,emersonbernier
Status: ASSIGNED → RESOLVED
Closed: 3 years ago
Resolution: --- → FIXED
Target Milestone: --- → 114 Branch
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: