Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1221365 - [RFE] Support GPOs from different domain controllers
[RFE] Support GPOs from different domain controllers
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: sssd (Show other bugs)
6.6
Unspecified Unspecified
medium Severity medium
: rc
: ---
Assigned To: SSSD Maintainers
Namita Soman
Aneta Šteflová Petrová
: FutureFeature
Depends On: 1217559
Blocks:
  Show dependency treegraph
 
Reported: 2015-05-13 16:54 EDT by Jakub Hrozek
Modified: 2016-05-10 16:22 EDT (History)
13 users (show)

See Also:
Fixed In Version: sssd-1.13.2-1.el6
Doc Type: Release Note
Doc Text:
SSSD now supports GPOs from different domain controllers The System Security Services Daemon (SSSD) service has been updated to support group policy objects (GPOs) from different domain controllers.
Story Points: ---
Clone Of: 1217559
Environment:
Last Closed: 2016-05-10 16:22:54 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Verification Logs (168.79 KB, text/plain)
2016-03-01 23:51 EST, Dan Lavu
no flags Details


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2016:0782 normal SHIPPED_LIVE sssd bug fix and enhancement update 2016-05-10 18:36:00 EDT

  None (edit)
Description Jakub Hrozek 2015-05-13 16:54:24 EDT
+++ This bug was initially created as a clone of Bug #1217559 +++

This bug is created as a clone of upstream ticket:
https://fedorahosted.org/sssd/ticket/2645

We decided to deny access to fix crash in ticket #2629.
It was short time solution for GPOs from different domain controller.

@see details in thread https://lists.fedorahosted.org/pipermail/sssd-devel/2015-April/023279.html
Comment 2 Jakub Hrozek 2015-06-03 09:00:15 EDT
master:
    c9db9d3e3d1a51117a64b366ec866bbeb009c57f
    31bafc0d6384a30859aa18f3bd22275aec6ee2ed
Comment 4 Dan Lavu 2016-03-01 23:51 EST
Created attachment 1132144 [details]
Verification Logs
Comment 5 Dan Lavu 2016-03-01 23:54:21 EST
Manually verified against sssd-1.13.3-15.el6.x86_64, full logs attached. 

#### output

ssh denied@sub.domain.com@192.168.76.3
denied@sub.domain.com@192.168.76.3's password:
Connection closed by 192.168.76.3

ssh allowed@sub.domain.com@192.168.76.3
allowed@sub.domain.com@192.168.76.3's password:
Last login: Tue Mar  1 23:41:15 2016 from 192.168.71.16

[allowed@sub.domain.com@sssdqe1 ~]$ hostname
sssdqe1.domain.com

#### config file


[sssd]
config_file_version = 2
services = nss, pam
domains = domain.com

[nss]
default_shell = /bin/bash

[domain/domain.com]
debug_level = 0xFFF0
id_provider = ad
ad_domain = domain.com
cache_credentials = True
krb5_store_password_if_offline = True
use_fully_qualified_names = True
fallback_homedir = /home/%d/%u
ad_gpo_access_control = enforcing
access_provider = ad
Comment 7 errata-xmlrpc 2016-05-10 16:22:54 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-0782.html

Note You need to log in before you can comment on or make changes to this bug.