Bug 1201840 - SSSD downloads too much information when fetching information about groups
Summary: SSSD downloads too much information when fetching information about groups
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: sssd
Version: 7.0
Hardware: Unspecified
OS: Unspecified
urgent
urgent
Target Milestone: rc
: ---
Assignee: SSSD Maintainers
QA Contact: Kaushik Banerjee
URL:
Whiteboard:
: 1207970 (view as bug list)
Depends On:
Blocks: 1201847 1214286
TreeView+ depends on / blocked
 
Reported: 2015-03-13 15:31 UTC by Jakub Hrozek
Modified: 2020-05-02 18:00 UTC (History)
16 users (show)

Fixed In Version: sssd-1.12.2-60.el7
Doc Type: Bug Fix
Doc Text:
Cause: SSSD downloaded the complete nested groups when looking up groups by SID, especially during tokenGroups processing when SSSD was configured with AD back end and disabled ID mapping Consequence: initgroups operation (and by extension "id" processing and logins) were taking too long Fix: Only information about the group itself and not its members is downloaded Result: Logins are and ID processing are faster now for setups with AD back end and disabled ID mapping.
Clone Of:
: 1201847 1214286 (view as bug list)
Environment:
Last Closed: 2015-11-19 11:36:15 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Github SSSD sssd issues 3642 None closed SSSD downloads too much information when fetching information about groups 2020-06-15 14:34:03 UTC
Github SSSD sssd issues 3655 None closed id lookup resolves "Domain Local" group and errors appear in domain log 2020-06-15 14:34:02 UTC
Red Hat Product Errata RHSA-2015:2355 normal SHIPPED_LIVE Low: sssd security, bug fix, and enhancement update 2015-11-19 10:27:42 UTC

Description Jakub Hrozek 2015-03-13 15:31:25 UTC
This bug is created as a clone of upstream ticket:
https://fedorahosted.org/sssd/ticket/2601

Currently SSSD downloads the complete nested groups when looking up groups by SID, especially during tokenGroups processing. We should only download the information about the group object itself, not the contents of the group

Comment 3 Jakub Hrozek 2015-04-08 08:02:31 UTC
Fixed upstream:
    master: d81d8d3dc151ebc95cd0e3f3b14c1cdaa48980f1
    sssd-1-12: b8d9eca0d9469c1209161b31a0109d8e4ea2868c

Comment 4 Jakub Hrozek 2015-04-09 06:42:52 UTC
*** Bug 1207970 has been marked as a duplicate of this bug. ***

Comment 8 Jakub Hrozek 2015-04-14 12:27:18 UTC
Lukas' patches that fixed the regression:
    master:
        b9fbeb75e7a4f50f98d979a70a710f9221892483
        bad2fc8133d941e5a6c8d8016c9689e039265c61
        5d864e7a9d0e1e6fb7dd8158c5b8bfb71040b908 
    sssd-1-12:
        49895bb18508a4f4b83b99d9875e99e17c81285b
        bdd031d274659263db5f28408d8b75c63d3485a0
        cf7047634308c431f4cfbff1d88564668d2a33c7

Comment 9 Jakub Hrozek 2015-04-14 12:29:55 UTC
Upstream ticket:
https://fedorahosted.org/sssd/ticket/2614

Comment 20 Nirupama Karandikar 2015-07-24 06:41:42 UTC
Verified via automation run against large no. of user and group sets on AD. Verified in sssd-1.13.0-5.el7.x86_64.rpm

Comment 21 errata-xmlrpc 2015-11-19 11:36:15 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHSA-2015-2355.html


Note You need to log in before you can comment on or make changes to this bug.