Bug 1084166
| Summary: | AD user sync broken with update | ||
|---|---|---|---|
| Product: | [Fedora] Fedora EPEL | Reporter: | Orion Poplawski <orion> |
| Component: | 389-ds-base | Assignee: | Rich Megginson <rmeggins> |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | urgent | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | el5 | CC: | edewata, mreynolds, nhosoi, nkinder, rmeggins |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | 389-ds-base-1.3.1.10-1 | Doc Type: | Bug Fix |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2015-04-29 19:08:16 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Orion Poplawski
2014-04-03 17:55:00 UTC
Thank you for your report. May I ask you to try one thing? Recently, we had a similar report and it turned out the reporter's indexes were some how outdated. The index files were ntUniqueId.db4 and ntUserDomainId.db4. Once they reindexed them, it started working for them. Could you try that? Thanks. That does not appear to help. Reindexed everything in userRoot too. Anything else to try? Thanks. We fixed these winsync related bugs since we moved to trac ticket (about 2 years ago). Do you see any fix which could be related to your case? (Please check the tickets which milestone is 1.3.0 or newer.) https://fedorahosted.org/389/query?status=closed&component=Sync+Service&order=milestone&desc=1&report=16&col=id&col=summary&col=status&col=type&col=priority&col=milestone&col=component Thanks. This problem is specific to EL5 and is likely due to some difference between our support for mozldap vs. openldap. I am able to reproduce the problem on EL5. This was likely broken when we switched EL5 over to 389-ds-base-1.2.11. We had to do that because it was simply too difficult to keep backporting security errata and other critical bug fixes to 1.2.10/1.2.9. We are working on a fix and hope to have something soon. No, not just el5/mozldap. This is the culprit: https://fedorahosted.org/389/ticket/47492 - we need to re-fix this ASAP. Upstream ticket: https://fedorahosted.org/389/ticket/47492 Any packages we can test? Is this in 389-ds-base-1.2.11.29-1.el5? (In reply to Orion Poplawski from comment #8) > Any packages we can test? Is this in 389-ds-base-1.2.11.29-1.el5? Yes, it is. http://directory.fedoraproject.org/wiki/Releases/1.2.11.29 Ticket 47492 - PassSync removes User must change password flag on the Windows side |