- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Segmentation fault on `show configuration user...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Segmentation fault on `show configuration user`
I ran into Segmentation fault on `show configuration user` on a customer.
Which breaks also the `show configuration` command as a whole.
I started tick 6-0003764714 as the issue was not on any of the normal users I investigated as part of sk181503 .
But Check Point support found the issue with the cpsho_user which was lacking a homedir. And that user was totally unknown to me. But then I stumbled into sk181305 .
I found the issue on multiple customers that have been upgraded to R81.10 or R81.20 so far.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please refer to sk181626 "show configuration user" command fails with "Segmentation fault" on the Security Management Server:
https://support.checkpoint.com/results/sk/sk181626
It should be fixed in JHF listed in the SK
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There have been a few posts on this topic also.
Checking the configuration of the cpsho_user seems like an easy thing to do if you encounter the error.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Interesting...will test this Thursday in my lab and report back, as I have everything on R81.20 jumbo 38.
Regards,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just tested, R81.20 jumbo 38, tested 6 machines, none had a problem.
Output from the mgmt server.
Andy
CP-management> show configuration user
set user admin shell /bin/bash
set user admin password-hash $6$rounds=10000$DcYQF3mR$7DC.LH6mWOTD0whVsqZNGacWzUFgdw/Hvs4RhbE8IYkIrTJtVkmRz3VPQskBQYhQY/OanpB8nzqQNugZQEIT11
set user monitor shell /etc/cli.sh
set user monitor password-hash *
CP-management>
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
any hit within /etc/passwd or /etc/shadow ?
Is web SmartConsole working fine ?
sk181305 says that the platform is Smart-1 only. It might be that such a user is created only on physical Smart-1 appliances and not on VMs ?
Also not sure if running SMS vs. MDS might be the difference here...
Jozko Mrkvicka
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
interesting discussion (or fight) already opened:
Jozko Mrkvicka
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Agree...definitely related.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
I'm happy to update that this issue has a fix, ready to be released.
The fix will be released as part of the next R81.10 and R81.20 jumbo hotfixes.
R81.20 JHF is expected to be released during this month, and R81.10 JHF towards end of 2023.
If a private fix is required, please refer to sk181626 to get a hotfix.
Best Regards,
Itai
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yup, We just ran into this. Upgraded all 4 of our Managers from Jumbo 110 to 130. Could not do several commands or even a show configuration on any of them without segmentation error. Put the directory for cpsho_user. now all commands work including our back product.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please refer to sk181626 "show configuration user" command fails with "Segmentation fault" on the Security Management Server:
https://support.checkpoint.com/results/sk/sk181626
It should be fixed in JHF listed in the SK
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the SK, but in our case our R81.20 Managers were fine, and this user (cpsho_user) was not added by Check Point. The problem happened because Check Point added this user (cpsho_user) in our R81.10 Managers. By the way our NERC-CIP auditors are going to have a good time with this one!!!
The SK should be a bit clearer. For example, it should maybe mention that even if the user you're logging in with has everything correct it still does not matter and still produces this segmentation fault. ALL users in the system need to be correct with all the correct configuration information. In our case cpsho_user was added by some Check Point jumbo or process without adding a home directory. There does not seem to be a jumbo take for R81.10 that addresses this?
-pat
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Pat,
I have sent this to the relevant owners in R&D.
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Talked to R&D and TLM owners. It should also be fixed in the upcoming R81.10 JHF, probably in January.
