Bug 1201840

Summary: SSSD downloads too much information when fetching information about groups
Product: Red Hat Enterprise Linux 7 Reporter: Jakub Hrozek <jhrozek>
Component: sssdAssignee: SSSD Maintainers <sssd-maint>
Status: CLOSED ERRATA QA Contact: Kaushik Banerjee <kbanerje>
Severity: urgent Docs Contact:
Priority: urgent    
Version: 7.0CC: ekeck, gagriogi, grajaiya, jgalipea, jhrozek, ldelouw, lslebodn, mkosek, mzidek, nkarandi, parsonsa, pbrezina, preichl, sbeal, sssd-maint, tscherf
Target Milestone: rcKeywords: ZStream
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: sssd-1.12.2-60.el7 Doc Type: Bug Fix
Doc Text:
Cause: SSSD downloaded the complete nested groups when looking up groups by SID, especially during tokenGroups processing when SSSD was configured with AD back end and disabled ID mapping Consequence: initgroups operation (and by extension "id" processing and logins) were taking too long Fix: Only information about the group itself and not its members is downloaded Result: Logins are and ID processing are faster now for setups with AD back end and disabled ID mapping.
Story Points: ---
Clone Of:
: 1201847 1214286 (view as bug list) Environment:
Last Closed: 2015-11-19 11:36:15 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1201847, 1214286    

Description Jakub Hrozek 2015-03-13 15:31:25 UTC
This bug is created as a clone of upstream ticket:
https://fedorahosted.org/sssd/ticket/2601

Currently SSSD downloads the complete nested groups when looking up groups by SID, especially during tokenGroups processing. We should only download the information about the group object itself, not the contents of the group

Comment 3 Jakub Hrozek 2015-04-08 08:02:31 UTC
Fixed upstream:
    master: d81d8d3dc151ebc95cd0e3f3b14c1cdaa48980f1
    sssd-1-12: b8d9eca0d9469c1209161b31a0109d8e4ea2868c

Comment 4 Jakub Hrozek 2015-04-09 06:42:52 UTC
*** Bug 1207970 has been marked as a duplicate of this bug. ***

Comment 8 Jakub Hrozek 2015-04-14 12:27:18 UTC
Lukas' patches that fixed the regression:
    master:
        b9fbeb75e7a4f50f98d979a70a710f9221892483
        bad2fc8133d941e5a6c8d8016c9689e039265c61
        5d864e7a9d0e1e6fb7dd8158c5b8bfb71040b908 
    sssd-1-12:
        49895bb18508a4f4b83b99d9875e99e17c81285b
        bdd031d274659263db5f28408d8b75c63d3485a0
        cf7047634308c431f4cfbff1d88564668d2a33c7

Comment 9 Jakub Hrozek 2015-04-14 12:29:55 UTC
Upstream ticket:
https://fedorahosted.org/sssd/ticket/2614

Comment 20 Nirupama Karandikar 2015-07-24 06:41:42 UTC
Verified via automation run against large no. of user and group sets on AD. Verified in sssd-1.13.0-5.el7.x86_64.rpm

Comment 21 errata-xmlrpc 2015-11-19 11:36:15 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHSA-2015-2355.html