Bug 2152177

Summary: [RFE] Add support for ldapi:// URLs
Product: Red Hat Enterprise Linux 9 Reporter: Graham Leggett <minfrin>
Component: sssdAssignee: Alexey Tikhonov <atikhono>
Status: CLOSED ERRATA QA Contact: Anuj Borah <aborah>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 9.2CC: aboscatt, atikhono, pasik, pbrezina, pkettman
Target Milestone: rcKeywords: FutureFeature, Triaged
Target Release: ---Flags: pm-rhel: mirror+
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: sync-to-jira
Fixed In Version: sssd-2.9.0-1.el9 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-11-07 08:54:17 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Graham Leggett 2022-12-09 15:43:26 UTC
Description of problem:

Teach sssd how to connect to an LDAP server over unix domain sockets (ldapi://).

Version-Release number of selected component (if applicable):

2.7.3-4.el9

How reproducible:

Always

Steps to Reproduce:
1. Connect to ldapi URL
2.
3.

Actual results:

Sadness.

Expected results:

Joy.

Additional info:

Patch to implement this here: https://github.com/SSSD/sssd/pull/6484

Backports clean to v2.7.3.

Comment 1 Alexey Tikhonov 2022-12-09 16:14:56 UTC
Probably would be make sense re-open bz 1897566

Comment 3 Alexey Tikhonov 2023-04-24 15:19:08 UTC
* `master`
  * e004595ae3d61b8f03886e185d270fd64f79513f - Don't force TLS on if we're a unix domain socket.
  * 2d54cf5eb5d4f90f7207d168e9c08261a5e74445 - Rename sdap_get_server_ip_str() to sdap_get_server_peer_str()
  * 4ccd5b9ac138efbd35379247e38f5db23bce8d87 - Do not set SO_KEEPALIVE on AF_UNIX.
  * 91b701232bfcf00b554efbabb264119bb60ee596 - Ensure we touch sockaddr_len in the success case only.
  * f221341813bd38352a6c8ffef960e08b8aa3080c - Align sockaddr_storage to sockaddr for updated API.
  * 9f2d8d69159478904ffff84717776118fbbc5281 - Add support for ldapi:// URLs.

Comment 9 errata-xmlrpc 2023-11-07 08:54:17 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (sssd bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2023:6644