Description of problem:
Currently auto_private_groups option is permanently enabled for the user from the subdomain. auto_private_group option can be disabled for user from the domain integrated directly. Same behavior should be extended for the users from the other subdomain as well.
Version-Release number of selected component (if applicable):
~]# rpm -q sssd
sssd-1.16.0-16.el7.x86_64
How reproducible:
Alwasy
Steps to Reproduce:
1. Join the rhel-system to the AD-server having at least one child domain.
2. set the 'auto_private_groups' option to the 'false' in the sssd.conf
3. run the 'id' against the users from the child domain.
Actual results:
~]# id user1_dom2-2316389
uid=494817046(user1_dom2-2316389) gid=494817046(user1_dom2-2316389) groups=494817046(user1_dom2-2316389),494817047(group1_dom2-2316389),494800513(domain users)
Expected results:
~]# id user1_dom2-2316389
uid=494817046(user1_dom2-2316389) gid=494817047(group1_dom2-2316389)
groups=494817047(group1_dom2-2316389),494817047(group1_dom2-2316389),494800513(domain users)
Additional info:
Let's track is upstream only to avoid rolling the bug report from one release to another.
If you disagree with closing this bug, please just reopen it.