Back to bug 805921

Who When What Removed Added
Jenny Severance 2012-06-13 20:15:26 UTC Priority unspecified low
Flags needinfo?(sgallagh)
Jenny Severance 2012-09-21 18:17:24 UTC QA Contact seceng-idm-qe-list kbanerje
Dennis Gregorovic 2012-10-04 18:35:29 UTC Assignee sgallagh jhrozek
Jakub Hrozek 2012-10-07 22:03:48 UTC Flags needinfo?(sgallagh)
Jakub Hrozek 2012-10-08 08:24:50 UTC Status NEW ASSIGNED
Jakub Hrozek 2012-10-10 09:13:22 UTC Status ASSIGNED MODIFIED
errata-xmlrpc 2012-10-10 10:08:53 UTC Status MODIFIED ON_QA
Eliska Slobodova 2012-11-15 14:59:28 UTC Doc Text Sometimes, group members may not be visible when running the getent group groupname command. This can be caused by an incorrect ldap_schema in the [domain/DOINNAME] section of the sssd.conf file. SSSD supports three LDAP schema types: RFC 2307 RFC 2307bis, and IPA. By default, SSSD uses the more common RFC 2307 schema. The difference between RFC 2307 and RFC 2307bis is the way which group membership is stored in the LDAP server. In an RFC 2307 server group members are stored as the multi-valued memberuid attribute which contains the name of the users that are members. In an RFC2307bis server group members are stored as the multi-valued attribute member (or sometimes uniqueMember) which contains the DN of the user or group that is a member of this group. RFC2307bis allows nested groups to be maintained as well.

When encountering this problem:

add ldap_schema = rfc2307bis in the sssd.conf file,

detele the /var/lib/sss/db/cache_DOMAINNAME.ldb file,

and restart SSSD.

If the workaround does not work, add ldap_group_member = uniqueMember in the sssd.conf file delete the cache file and restart SSSD.
Doc Type Bug Fix Known Issue
Kaushik Banerjee 2013-01-30 13:56:59 UTC Status ON_QA VERIFIED
errata-xmlrpc 2013-02-21 09:21:58 UTC Status VERIFIED CLOSED
Resolution --- ERRATA
Last Closed 2013-02-21 04:21:58 UTC
Pavel Březina 2020-05-02 16:48:35 UTC Link ID Github SSSD/sssd/issues/2298

Back to bug 805921