sk181626 - "show configuration user" command fails with "Segmentation fault" on the Security Management Server

"show configuration user" command fails with "Segmentation fault" on the Security Management Server

Product

Multi-Domain Security Management, Security Gateways, Security Management

Version

R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20

OS

Gaia

Last Modified

2024-01-14

Symptoms

Example:

HostName> show configuration user

add user cpsho_user uid 208 homedir /home/cpsho_user

set user cpsho_user gid 100 shell /etc/cli.sh<

set user cpsho_user password-hash XXXXXX

... ... ...

Segmentation fault

Example:

kernel:clish[xxxxx]: segfault at 0 ip 00000000f5078a5f sp 00000000ffeeb3b0 error 4 in
libcli_passwd.so[f5072000+e000]

Cause

An administrator configured one or more of the users incorrectly.

Solution

This problem was fixed. The fix is included starting from:

Check Point recommends to always upgrade to the Recommended version (Security Management Server / Multi-Domain Security Management Server / SmartConsole).

If you choose not to upgrade, contact Check Point Support to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

For faster resolution and verification, collect the CPinfo file from the Management Server involved in the case.

Hotfix installation instructions: Refer to sk168597 - How to install a Hotfix.

Workaround

This immediate workaround is available:

  1. Connect to the command line on the Management Server.
  2. Log in to the Expert mode.
  3. Examine the user configuration in the Gaia Database:
grep "passwd:<UserName>" /config/active

Example of a Correct User Configuration

This example shows the correct configuration entries for the username "cpsho_user":

[Expert@MGMT:0]# grep "passwd:cpsho_user" /config/active
passwd:cpsho_user t
passwd:cpsho_user:uid 1000
passwd:cpsho_user:gid 100
passwd:cpsho_user:homedir /home/USER1
passwd:cpsho_user:passwd XXXXXXXXX
passwd:cpsho_user:realname USER1
passwd:cpsho_user:shell /etc/cli.sh

How to add a missing entry to a user configuration

If an entry is missing, use Gaia Clish commands to add it.

In the example below, the "homedir" entry is missing for the "cpsho_user":

[Expert@fw1:0]# grep "passwd:cpsho_user" /config/active
passwd:cpsho_user t
passwd:cpsho_user:uid 1000
passwd:cpsho_user:gid 100
passwd:cpsho_user:passwd XXXXXXXXX
passwd:cpsho_user:realname cpsho_user
passwd:cpsho_user:shell /etc/cli.sh
passwd:cpsho_user:lastchg 1675072263

In the example above, use these Gaia Clish commands to configure a home directory:

MGMT> set user cpsho_user homedir /home/cpsho_user
MGMT> save config

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.