| Summary: | Need support for OpenDirectory in LDAP driver in RHOSP 8.0 | ||
|---|---|---|---|
| Product: | Red Hat OpenStack | Reporter: | Jeremy <jmelvin> |
| Component: | openstack-keystone | Assignee: | Adam Young <ayoung> |
| Status: | CLOSED ERRATA | QA Contact: | Rodrigo Duarte <rduartes> |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | 8.0 (Liberty) | CC: | ayoung, ealcaniz, jdennis, mlopes, mschuppe, nkinder, nlevinki, pablo.iranzo, srevivo |
| Target Milestone: | async | Keywords: | ZStream |
| Target Release: | 8.0 (Liberty) | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | openstack-keystone-8.0.1-3.el7ost | Doc Type: | Bug Fix |
| Doc Text: |
In certain cases, directories use the concept of POSIX groups, where the entities of users in the groups are represented as UIDs, not full DNs such as:
dn: cn=group1, cn=groups,dc=domain,dc=com
....
memberUid: user1
memberUid: user2
....
The LDAP driver was previously hardcoded for full DN entities, for example:
dn: cn=group1, cn=groups,dc=domain,dc=com
....
memberUid: uid=user1,cn=users,dc=domain,dc=com
memberUid: uid=user2,cn=users,dc=domain,dc=com
....
This update adds support for LDAP backends using POSIX groups.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2016-11-14 19:58:29 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Jeremy
2016-09-13 17:07:49 UTC
There are two patches that are required to completely solve this issue according to the launchpad thread: https://review.openstack.org/258528 is the patch linked above The additional changes are: https://review.openstack.org/#/c/291497/ which solves a problem described here: https://bugs.launchpad.net/keystone/+bug/1526462/comments/12 Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2016-2711.html |