From Fedora Project Wiki

Fedora Test Days
Features/FreeIPA_Two_Factor_Authentication

Date 2013-06-06 to 2013-06-07
Time all day both days

Website QA/Fedora_19_test_days
IRC #fedora-test-day (webirc)


TEST DAY EXTENDED
Please note that due to the lack of advance notice, the Test Day has been extended to 2013-06-07. QA folks and developers will be around both days to take results and help with troubleshooting. If you were interested in the event but the notice was too short to make it on 2013-06-06, just come along the next day!
Can't make the date?
If you come to this page before or after the test day is completed, your testing is still valuable, and you can use the information on this page to test, file any bugs you find at Bugzilla, and add your results to the results section. If this page is more than a month old when you arrive here, please check the current schedule and see if a similar but more recent Test Day is planned or has already happened.

What to test?[edit]

Today's instalment of Fedora Test Day will focus on FreeIPA Two Factor Authentication.

Who's available[edit]

The following cast of characters will be available testing, workarounds, bug fixes, and general discussion ...

Feedback[edit]

We need your feedback!

Prerequisite for Test Day[edit]

  • A live image. Tips on using a live image are available at FedoraLiveCD.
Architecture SHA256SUM
x86_64 9cc3f8884df74dc4b61636dcf3ff6b2f7a19d1f034078722112a7944ddc72c45
i686 a924364c313b21006b4efaca02b549b6cd1eab13a4adb85233265d2cb3b66c3e
Memory
Please make sure that the LiveCD has enough memory to operate. We recommend:
  • At minimum 2.5 GB of memory for non-graphical run
  • At minimum 3 GB memory for graphical (GNOME) run
  • Fedora 19 prepared with the following instructions (run as root):
# Get environment script
wget http://npmccallum.fedorapeople.org/freeipa-otp/ipa-testday-env

# If you have mod_ssl installed, it will cause a conflict during environment install
yum remove mod_ssl

# Install FreeIPA 2FA test environment
bash ipa-testday-env install

# When testing is complete, remove the test environment
bash ipa-testday-env uninstall
Package updates
An updated libbsd package is causing the Kerberos database to not be created which causes the IPA installation to fail. Do not update the libbsd package to libbsd-0.5.1-1. libbsd-0.4.2-3 is known to work.

Test Cases[edit]

Install/Setup Tests:

3rd Party RADIUS
If you have tested against a 3rd party RADIUS server, please provide the name and version of this server in the table below.

Test Results[edit]

Construct a table or list to allow testers to post results. Each column should be a test case or configuration, and each row should consist of test results. Include some instructions on how to report bugs, and any special instructions. Here's an example, from a Palimpsest test day:

If you have problems with any of the tests, report a bug to Bugzilla usually for the component freeipa, or krb5. If you are unsure about exactly how to file the report or what other information to include, just ask on IRC and we will help you. Once you have completed the tests, add your results to the Results table below, following the example results from the first line as a template. The first column should be your name with a link to your User page in the Wiki if you have one. For each test case, use the result template to enter your result, as shown in the example result line.

User Basic installation tests Internal OTP External OTP Other 3rd Party RADIUS References
Sample User
none
Pass pass
Warning warn
[1]
Fail fail
[2]
FreeRADIUS 2.2.0,

RSA Authentication Manager 8.0

  1. Test pass, but also encountered RHBZ #54321
  2. RHBZ #12345
Rob Crittenden
Pass pass
Pass pass
Warning warn
[1]
none
Internal
  1. Test pass, radius user not visible. https://fedorahosted.org/freeipa/ticket/3693
Frank Jayalath
Fail fail [1]
none
none
none
Internal
  1. RHBZ #971639
Tomas Babej
Pass pass
Pass pass
Pass pass
none
Internal
Chris Hudson
Pass pass
Warning warn
[long 1]
Pass pass
none
Internal

Long comments[edit]

  1. Test pass, QR code would only scan on iOS after making the keylength 30 (divisible by 5) https://code.google.com/p/google-authenticator/issues/detail?id=268