Bug 806209
Summary: | ldap_user_authorized_host = gecos doesn't work | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 7 | Reporter: | Kaushik Banerjee <kbanerje> |
Component: | sssd | Assignee: | SSSD Maintainers <sssd-maint> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | Namita Soman <nsoman> |
Severity: | unspecified | Docs Contact: | |
Priority: | unspecified | ||
Version: | 7.0 | CC: | dpal, grajaiya, jgalipea, jhrozek, prc |
Target Milestone: | rc | ||
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2016-01-07 13:01:17 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Kaushik Banerjee
2012-03-23 08:08:17 UTC
This issue can be reproduced only when I set "ldap_user_authorized_host = gecos". I added added another ldap attribute "description: host1.example.com" to the user and the issue is no longer seen when I set "ldap_user_authorized_host = description". Also, I tried with "ldap_user_gecos = description" and "ldap_user_authorized_host = gecos" and it works fine in this case. This is the case because you have used gecos for *both* user's gecos and the authorizedHost attribute. In this case, the first match (which is user's gecos) wins. As you noted, everything works fine if you also mapped the ldap_user_gecos attribute onto something else. I don't think this is a bug. (In reply to comment #3) > This is the case because you have used gecos for *both* user's gecos and the > authorizedHost attribute. In this case, the first match (which is user's gecos) > wins. > > As you noted, everything works fine if you also mapped the ldap_user_gecos > attribute onto something else. > > I don't think this is a bug. It is a bug. We're supposed to be explicitly handling the possibility of having the same attribute address act as more than one option. This was added so we could support using "cn" for multiple options (specifically). Upstream ticket: https://fedorahosted.org/sssd/ticket/1279 This functionality was implemented in commit eed2073f6f7bed7df0327b9fc0f2d410975d5332 which made it to upstream release 1.12 |