Bug 1127266
| Summary: | Problems with tokengroups and ldap_group_search_base | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Jakub Hrozek <jhrozek> |
| Component: | sssd | Assignee: | Jakub Hrozek <jhrozek> |
| Status: | CLOSED ERRATA | QA Contact: | Kaushik Banerjee <kbanerje> |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | 7.1 | CC: | ddas, dpal, drieden, grajaiya, jgalipea, kbanerje, lslebodn, mkosek, pbrezina, preichl |
| Target Milestone: | rc | Keywords: | Regression |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | sssd-1.12.1-1.el7 | Doc Type: | Bug Fix |
| Doc Text: |
Cause: When a non-standard group search base was used, the ID provider might be restricted so that it doesn't allow to resolve all group GIDs returned by the tokenGroups attribute during initgroups call.
Consequence: The admin restricted the search base in order to only see certain groups in the 'id output' However, all group GIDs would be reported, with those outside the group base available only as numerical GIDs, not group names.
Fix: We documented that if restricting the group search base, tokengroups support must be disabled manually.
Result: With disabled tokengroups support and restricted group search base, only the groups in the restricted group search base are visible and all the GIDs resolve into group names.
|
Story Points: | --- |
| Clone Of: | 1127265 | Environment: | |
| Last Closed: | 2015-03-05 10:33:12 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1127265 | ||
| Bug Blocks: | |||
|
Description
Jakub Hrozek
2014-08-06 13:45:33 UTC
This was fixed in master some time ago:
master: 983983dd1629ab33eab340a40d9ee83965a339c6
sssd-1-11: 6e6c099b02014d6e2ed97a057c6c521db9c30139
Verified with 1.12.2-28.el7 :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: [ LOG ] :: bug_automation_007: Problems with tokengroups and ldap_group_search_base :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: [ PASS ] :: Command 'id testuser05-817192' (Expected 0, got 0) :: [ PASS ] :: File '/var/log/sssd/sssd_sssdad2012.com.log' should not contain 'No ID ctx available for \[sssdad2012.com\]' :: [ LOG ] :: Duration: 5s :: [ LOG ] :: Assertions: 2 good, 0 bad :: [ PASS ] :: RESULT: bug_automation_007: Problems with tokengroups and ldap_group_search_base Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2015-0441.html |