Bug 1819012
| Summary: | [RFE] Improve AD site discovery process | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | toasty <wrydberg> |
| Component: | sssd | Assignee: | Pavel Březina <pbrezina> |
| Status: | CLOSED ERRATA | QA Contact: | Dan Lavu <dlavu> |
| Severity: | unspecified | Docs Contact: | lmcgarry |
| Priority: | unspecified | ||
| Version: | 8.2 | CC: | apeddire, atikhono, dave, dlavu, grajaiya, jentrena, jhrozek, lslebodn, mzidek, pbrezina, thalman, tscherf |
| Target Milestone: | rc | Keywords: | FutureFeature, Triaged |
| Target Release: | --- | Flags: | pm-rhel:
mirror+
|
| Hardware: | Unspecified | ||
| OS: | Linux | ||
| Whiteboard: | sync-to-jira qetodo tested | ||
| Fixed In Version: | sssd-2.4.0-1.el8 | Doc Type: | Enhancement |
| Doc Text: |
.Improved Active Directory site discovery process
The SSSD service now discovers Active Directory sites in parallel over connection-less LDAP (CLDAP) to multiple domain controllers to speed up site discovery in situations where some domain controllers are unreachable. Previously, site discovery was performed sequentially and, in situations where domain controllers were unreachable, a timeout eventually occurred and SSSD went offline.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2021-05-18 15:03:54 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1881992 | ||
| Bug Blocks: | |||
|
Description
toasty
2020-03-30 23:40:31 UTC
Upstream ticket: https://pagure.io/SSSD/sssd/issue/2702 Upstream ticket migrated to https://github.com/SSSD/sssd/issues/3743 Upstream PR: https://github.com/SSSD/sssd/pull/5300 Dave, would you be willing to test a scratch build? Sure Pavel, but it might be a few weeks before I can turn that round because someone recently decided our lab environment needs to be isolated from the rest of our corporate network, so we're still in the process of arguing about what that isolation will look like! In the mean time, would you mind sending over any details I'll need to get the scratch build running (do I just follow https://sssd.io/docs/developers/contribute.html#building-sssd ?, do I need to run on el8? anything else...) Thanks Which el8 version do you run? I will give you a scratch build. Or if you prefer to build it on your own you can get the source here and then follow the link you found: https://github.com/pbrezina/sssd/tree/adsite-cldap-parallel Pushed PR: https://github.com/SSSD/sssd/pull/5300 * `master` * f0d650799d4390f90890d17c56a4e395e931d8cb - tevent: correctly handle req timeout error * 9fdf5cfacd1a425691d44db53897096887bb3e6f - ad: renew site information only when SSSD was previously offline * a62a13ae61d4e08b21e706df6ca266c38891f430 - man: fix typo in failover description * fcfd834c9d80d7690f938582335d81231a5f6e60 - ad: if all in-site dc are unreachable try off-site controllers * 1889ca60a9c642f0cca60b20a5b94de7a66924f6 - ad: connect to the first available server for cldap ping * 8265674a055e5cdb57acebad72d935356408540a - ad: use cldap for site and forrest discover (perform CLDAP ping) * 414593cca65ed09fe4659e2786370a4553664cd0 - ldap: add support for cldap and udp connections Pushed PR: https://github.com/SSSD/sssd/pull/5345 * `master` * 37ba37a425453d8222584176ae5975a795422091 - ad: fix handling of current site and forest in cldap ping Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (sssd bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2021:1666 |