Firefox flatpak unable to access kerberos ticket
Categories
(Core :: Widget: Gtk, defect, P3)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox114 | --- | fixed |
People
(Reporter: jan, Assigned: stransky)
References
(Blocks 1 open bug)
Details
Attachments
(1 file)
User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:82.0) Gecko/20100101 Firefox/82.0
Steps to reproduce:
-
Obtain kerberos ticket via
kinit -
Go to
about:configand setnetwork.negotiate-auth.trusted-uristo domain -
navigate to URL behind kerberos auth
Actual results:
Firefox does not authenticate using kerberos ticket (no access from inside flatpak sandbox).
Expected results:
Firefox flatpak should have access to kerberos tickets outside of the sandbox.
$ flatpak info org.mozilla.firefox
Firefox - Mozilla Firefox Web Browser
ID: org.mozilla.firefox
Ref: app/org.mozilla.firefox/x86_64/stable
Arch: x86_64
Branch: stable
Version: 82.0
License: MPL-2.0
Origin: flathub
Collection: org.flathub.Stable
Installation: system
Installed: 215,3 MB
Runtime: org.freedesktop.Platform/x86_64/19.08
Sdk: org.freedesktop.Sdk/x86_64/19.08
Commit: a0b41cf81fcc1766da9bf6a96f4514c81a35a0eeb5edc958e853607ed4687c28
Parent: 7226dd95603790172b8a67263b9c0754d4bc692149d6f1d54ddff1a2a9537842
Subject: Export org.mozilla.firefox
Date: 2020-10-20 12:47:44 +0000
| Reporter | ||
Comment 1•5 years ago
|
||
Here is bug where the same issue was addressed in Fedora's flatpak of Firefox: https://bugzilla.redhat.com/show_bug.cgi?id=1699235
Comment 2•5 years ago
|
||
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:82.0) Gecko/20100101 Firefox/82.0
Hi,
I will move this over to a component so developers can take a look over it. If this is not the correct component please feel free to change it to an appropriate one.
Thanks for the report.
Comment 3•5 years ago
|
||
Hi, with /etc/krb5.conf.d accessible to flatpak and cache set to KCM:
flatpak run --filesystem=/run/.heim_org.h5l.kcm-socket --filesystem=/etc/krb5.conf:ro $(for file in /etc/krb5.conf.d/* ; do echo --filesystem=${file}:ro; done) --env="KRB5CCNAME=KCM:" --env=NSPR_LOG_MODULES=timestamp,negotiateauth:5 org.mozilla.firefox
I got from this error:
2020-11-27 17:40:40.883571 UTC - [Parent 2: Main Thread]: D/negotiateauth nsHttpNegotiateAuth::ChallengeReceived URI blocked
To this error:
2020-11-28 09:27:35.708738 UTC - [Parent 2: Main Thread]: D/negotiateauth service = <URI>
2020-11-28 09:27:35.708783 UTC - [Parent 2: Main Thread]: D/negotiateauth using negotiate-gss
2020-11-28 09:27:35.708806 UTC - [Parent 2: Main Thread]: D/negotiateauth entering nsAuthGSSAPI::nsAuthGSSAPI()
2020-11-28 09:27:35.709342 UTC - [Parent 2: Main Thread]: D/negotiateauth Fail to load gssapi library
2020-11-28 09:27:35.709362 UTC - [Parent 2: Main Thread]: D/negotiateauth entering nsAuthGSSAPI::Init()
This didn't change when I added libs from krb5-libs package and tried to use them as network.negotiate-auth.gsslib, the error was then one line longer:
20-11-28 09:27:13.643067 UTC - [Parent 2: Main Thread]: D/negotiateauth service = <URI>
2020-11-28 09:27:13.643109 UTC - [Parent 2: Main Thread]: D/negotiateauth using negotiate-gss
2020-11-28 09:27:13.643121 UTC - [Parent 2: Main Thread]: D/negotiateauth entering nsAuthGSSAPI::nsAuthGSSAPI()
2020-11-28 09:27:13.643142 UTC - [Parent 2: Main Thread]: D/negotiateauth Attempting to load user specified library [/usr/lib64/libkrb5.so.3.3]
2020-11-28 09:27:13.643265 UTC - [Parent 2: Main Thread]: D/negotiateauth Fail to load gssapi library
2020-11-28 09:27:13.643281 UTC - [Parent 2: Main Thread]: D/negotiateauth entering nsAuthGSSAPI::Init()
If this issue had workaround with command line and about:config magic, it would be great!
Comment 4•5 years ago
|
||
I have the same problem with Flathub instance. But version from Fedora flatpak repository works fine.
Comment 5•5 years ago
|
||
There's a missing libgssapi.so in the runtime. I'm not sure from where it should get it ATM. Also to allow using gssapi you need to set the network.negotiate-auth.trusted-uris to the https:// (or what suits you better)
Comment 6•5 years ago
|
||
Unfortunately the kerberos has been removed from the freedesktop runtime: https://gitlab.com/freedesktop-sdk/freedesktop-sdk/-/commit/7a4ee266ee42852e73e5ddcadbcdd9a64759bedc so we need to find a way how to put it back. By trying to revert the change in the freedesktop or using an Extension: https://github.com/flatpak/flatpak/wiki/Extensions
Comment 7•5 years ago
|
||
(In reply to Jan Horak [:jhorak] from comment #6)
Unfortunately the kerberos has been removed from the freedesktop runtime: https://gitlab.com/freedesktop-sdk/freedesktop-sdk/-/commit/7a4ee266ee42852e73e5ddcadbcdd9a64759bedc so we need to find a way how to put it back. By trying to revert the change in the freedesktop or using an Extension: https://github.com/flatpak/flatpak/wiki/Extensions
The easiest way is to add it in baseapp[1] where every other FF optional dependency is stored.
Comment 8•5 years ago
|
||
This should be fixed through https://github.com/flathub/org.mozilla.firefox.BaseApp/commit/f8ef0b766cc23be262f5349947c0f2d3c4193b56
Comment 9•5 years ago
|
||
Unfortunately the fix does not seem to work
+++ Firefox via flathub
$ flatpak info org.mozilla.firefox
Firefox - Mozilla Firefox Web Browser
ID: org.mozilla.firefox
Ref: app/org.mozilla.firefox/x86_64/stable
Arch: x86_64
Branch: stable
Version: 91.0.2
License: MPL-2.0
Origin: flathub
Collection: org.flathub.Stable
Installation: system
Installed: 238.3 MB
Runtime: org.freedesktop.Platform/x86_64/20.08
Sdk: org.freedesktop.Sdk/x86_64/20.08
Commit: 8729eb0d73ae187b98cbf5ffb381dc25b6d7719f159a286a671b2ec387b60312
Parent: d79e470d18fa27270d2055723b7509876c6878158d38aef35f9fd296f6188806
Subject: Export org.mozilla.firefox
Date: 2021-08-24 12:47:04 +0000
$ cat /var/lib/flatpak/app/org.mozilla.firefox/x86_64/stable/active/files/etc/krb5.conf
[libdefaults]
dns_lookup_realm = false
ticket_lifetime = 24h
renew_lifetime = 7d
forwardable = true
rdns = false
pkinit_anchors = FILE:/etc/ssl/certs/ca-certificates.crt
spake_preauth_groups = edwards25519
default_ccache_name = KCM:
+++ Kerberos info
$ klist
Ticket cache: KCM:1000
Default principal: heytherethisisfake@IPA.REDHAT.COM
Valid starting Expires Service principal
24/08/21 18:25:04 25/08/21 04:25:04 krbtgt/IPA.REDHAT.COM@IPA.REDHAT.COM
renew until 25/08/21 18:25:02
24/08/21 18:25:08 25/08/21 04:25:04 HTTP/heytherethisisfake.redhat.com@
renew until 25/08/21 18:25:02
Ticket server: HTTP/heytherethisisfake.redhat.com@IPA.REDHAT.COM
+++ Firefox via fedora (this one does work)
$ flatpak info org.mozilla.Firefox
Firefox - Web Browser
ID: org.mozilla.Firefox
Ref: app/org.mozilla.Firefox/x86_64/stable
Arch: x86_64
Branch: stable
Version: 90.0.2
License: GPL-3.0+
Origin: fedora
Collection:
Installation: system
Installed: 280.7 MB
Runtime: org.fedoraproject.Platform/x86_64/f34
Sdk: org.fedoraproject.Sdk/x86_64/f34
Commit: 17e7729c765920d15d46ef4c9c5075d5a9df6c2010a8177aa53806c927ae3d9b
Subject: Export org.mozilla.Firefox
Date: 2021-07-23 15:12:42 +0000
Alt-id: b765534e3794397ea480a65d1e961eff32af141d7e3a81d80f14769e4ef4bac1
$ cat /var/lib/flatpak/runtime/org.fedoraproject.Platform/x86_64/f34/active/files/etc/krb5.conf
# To opt out of the system crypto-policies configuration of krb5, remove the
# symlink at /etc/krb5.conf.d/crypto-policies which will not be recreated.
includedir /etc/krb5.conf.d/
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[libdefaults]
dns_lookup_realm = false
ticket_lifetime = 24h
renew_lifetime = 7d
forwardable = true
rdns = false
pkinit_anchors = FILE:/etc/pki/tls/certs/ca-bundle.crt
spake_preauth_groups = edwards25519
dns_canonicalize_hostname = fallback
qualify_shortname = ""
# default_realm = EXAMPLE.COM
default_ccache_name = KEYRING:persistent:%{uid}
[realms]
# EXAMPLE.COM = {
# kdc = kerberos.example.com
# admin_server = kerberos.example.com
# }
[domain_realm]
# .example.com = EXAMPLE.COM
# example.com = EXAMPLE.COM
Comment 10•5 years ago
|
||
I confirm the same problem today with flathub firefox. Installing directly from the archlinux standard repository, without sandboxing, works fine with my kerberos tokens.
Comment 11•4 years ago
|
||
For me Kerberos works as excepted on Debian 11 (Bullseye) with the latest org.mozilla.firefox flatpak and the config given by David Jaša. This is what I did:
-
Install package
sssd-kcm -
Change Kerberos credential cache to KCM (already the default on Fedora?), e.g. with
export KRB5CCNAME=KCM:
-
Get a Kerberos ticket with
kiniton the host (not within the flatpak) -
Test Kerberos configuration in Firefox flatpak
flatpak run --command=bash --filesystem=/run/.heim_org.h5l.kcm-socket --filesystem=/etc/krb5.conf:ro --env="KRB5CCNAME=KCM:" org.mozilla.firefox
# run within firefox flatpak it should print the kerberos identities
klist
- Allow Firefox's flatpak to permanently access the KCM socket and Kerberos configuration
flatpak override --user --filesystem=/run/.heim_org.h5l.kcm-socket --filesystem=/etc/krb5.conf:ro --env="KRB5CCNAME=KCM:" org.mozilla.firefox
- Run Firefox flatpak and follow the steps to configure Firefox for GSSAPI, e.g. adding your domain to
network.negotiate-auth.trusted-urisinabout:config
When using a different Kerberos config file (instead of /etc/krb5.conf), then make sure to grant access to this file to flatpak (flatpak override --filesystem ... org.mozilla.firefox) and to set KRB5_CONFIG (flatpak override --env ... org.mozilla.firefox).
Comment 12•3 years ago
|
||
I've just tried with the current version of flathub Firefox on Fedora 37 and the only missing bit now it to expose the kerberos socket to the VM. A permanent setting can be using by an override:
# flatpak override --filesystem=/run/.heim_org.h5l.kcm-socket org.mozilla.firefox
I didn't have to add any other override (neither for /etc/krb5.conf nor for any KRB* environment variable). Given it's such a little change, I dared to open a PR for it. :)
| Assignee | ||
Comment 13•3 years ago
|
||
Updated•3 years ago
|
Comment 14•3 years ago
|
||
(In reply to David Jaša from comment #12)
I've just tried with the current version of flathub Firefox on Fedora 37 and the only missing bit now it to expose the kerberos socket to the VM. A permanent setting can be using by an override:
# flatpak override --filesystem=/run/.heim_org.h5l.kcm-socket org.mozilla.firefoxI didn't have to add any other override (neither for
/etc/krb5.confnor for anyKRB*environment variable). Given it's such a little change, I dared to open a PR for it. :)
So. The exposure of KCM socket is still less-then-ideal solution, it depends on krb5 assumptions within flatpak matching how is kerberos actually configured on the host system. gssproxy is the project that can provide kerberos stuff to the containers without a need to expose configuration or sockets from host system, it's available in flatpak since last year however it seems that we'd need to jump through some hoops if the situation is the same as last year. Luckily, these changes are stuff for flathub manifest so it's more accessible to contributors who don't use Mozilla's instance of mercurial regularly.
Comment 15•3 years ago
|
||
The gssproxy feature requires at least flatpak 14.x (latest Ubuntu LTS 22.04 has 12.x) plus relevant change must be available on host as well. This is some prospect for few years from now, currently adding filesystem permission is more reliable.
Comment 16•3 years ago
|
||
Comment 17•3 years ago
|
||
| bugherder | ||
Description
•