Bug 1356433

Summary: ldap_group_external_member is no set for the IPA provider
Product: Red Hat Enterprise Linux 7 Reporter: Marcel Kolaja <mkolaja>
Component: sssdAssignee: SSSD Maintainers <sssd-maint>
Status: CLOSED ERRATA QA Contact: Steeve Goveas <sgoveas>
Severity: high Docs Contact:
Priority: high    
Version: 7.2CC: grajaiya, jhrozek, ksiddiqu, lslebodn, mkosek, mmuehlfe, mvarun, mzidek, pbrezina, sbose, sssd-maint
Target Milestone: rcKeywords: ZStream
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: sssd-1.13.0-40.el7_2.12 Doc Type: Bug Fix
Doc Text:
Previously, the ldap_group_external_member parameter had no default value set. As a consequence, the System Security Services Daemon (SSSD) failed to resolve external members of IdM groups during getgr* requests. A patch has been applied to set a default value for the ldap_group_external_member parameter. As a result, resolving external members of IdM groups works in the described scenario.
Story Points: ---
Clone Of: 1346294 Environment:
Last Closed: 2016-08-02 18:38:00 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1346294    
Bug Blocks:    

Description Marcel Kolaja 2016-07-14 06:26:00 UTC
This bug has been copied from bug #1346294 and has been proposed
to be backported to 7.2 z-stream (EUS).

Comment 6 Varun Mylaraiah 2016-07-15 11:00:40 UTC
Verified
ipa-server-4.2.0-15.el7_2.18.x86_64
sssd-1.13.0-40.el7_2.12.x86_64
 
# ipa group-add testgrp02
-----------------------
Added group "testgrp02"
-----------------------
  Group name: testgrp02
  GID: 1929200020
 
 
# ipa group-add --desc='external group' ext_testgrp02 --external
---------------------------
Added group "ext_testgrp02"
---------------------------
  Group name: ext_testgrp02
  Description: external group
 
# ipa group-add-member ext_testgrp02 --external "ADTEST2.QE\adgroup1"
[member user]:
[member group]:
  Group name: ext_testgrp02
  Description: external group
  External member: S-1-5-21-1869981227-3608374679-2281468898-1106
-------------------------
Number of members added 1
-------------------------
 
# ipa group-add-member testgrp02
[member user]:
[member group]: ext_testgrp02
  Group name: testgrp02
  GID: 1929200020
  Member groups: ext_testgrp02
-------------------------
Number of members added 1
-------------------------

# getent group testgrp02
testgrp02:*:1929200020:aduser2,Aduser1

Comment 9 errata-xmlrpc 2016-08-02 18:38:00 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-1528.html