Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 1350309

Summary: External group-membership fix is incompatible with SSSD's default_domain_suffix option.
Product: Red Hat Enterprise Linux 7 Reporter: Marcel Kolaja <mkolaja>
Component: slapi-nisAssignee: Alexander Bokovoy <abokovoy>
Status: CLOSED ERRATA QA Contact: Kaleem <ksiddiqu>
Severity: high Docs Contact: Marc Muehlfeld <mmuehlfe>
Priority: high    
Version: 7.2CC: abokovoy, mkosek, mmuehlfe, mvarun, sbose, tscherf
Target Milestone: rcKeywords: ZStream
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
A previously updated version of slapi-nis introduced incompatibility of the slapi-nis external group-membership with the System Security Services Daemons (SSSD) default_domain_suffix option. As a consequence, the IPA compat-tree got inaccessible because external members of IPA groups could not be resolved during the initialization, and slapi-nis fails to start. A patch has been applied to fix the schema compatibility plug-in to work with SSSD, and slapi-nis is now compatible with the SSSD default_domain_suffix parameter.
Story Points: ---
Clone Of: 1346735 Environment:
Last Closed: 2016-08-02 18:35:50 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1346735    
Bug Blocks:    

Description Marcel Kolaja 2016-06-27 06:02:36 UTC
This bug has been copied from bug #1346735 and has been proposed
to be backported to 7.2 z-stream (EUS).

Comment 6 Varun Mylaraiah 2016-07-14 14:27:22 UTC
Verified
# rpm -qa slapi-nis* ipa-server
ipa-server-4.2.0-15.el7_2.18.x86_64
slapi-nis-0.54-11.el7_2.x86_64

Step 1: configured ipa with AD  
Step 2: added default_domain_suffix = ad.domain in /etc/sssd/sssd.conf
Step 3: restart ipa server(ipactl restart)

Got expected output ('schema-compat-plugin - Finished plugin initialization.') in /var/log/dirsrv/slapd-HTESTRELM-TEST/errors

Log output:
/var/log/dirsrv/slapd-HTESTRELM-TEST/errors

[14/Jul/2016:04:34:41 -0400] schema-compat-plugin - schema-compat-plugin tree scan will start in about 5 seconds!
[14/Jul/2016:04:34:41 -0400] - slapd started.  Listening on All Interfaces port 389 for LDAP requests
[14/Jul/2016:04:34:41 -0400] - Listening on All Interfaces port 636 for LDAPS requests
[14/Jul/2016:04:34:41 -0400] - Listening on /var/run/slapd-HTESTRELM-TEST.socket for LDAPI requests
[14/Jul/2016:04:34:41 -0400] slapd_ldap_sasl_interactive_bind - Error: could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -1 (Can't contact LDAP server) ((null)) errno 2 (No such file or directory)
[14/Jul/2016:04:34:41 -0400] slapi_ldap_bind - Error: could not perform interactive bind for id [] authentication mechanism [GSSAPI]: error -1 (Can't contact LDAP server)
[14/Jul/2016:04:34:41 -0400] NSMMReplicationPlugin - agmt="cn=meToreplica1.htestrelm.test" (replica1:389): Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) ()
[14/Jul/2016:04:34:42 -0400] slapd_ldap_sasl_interactive_bind - Error: could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -1 (Can't contact LDAP server) ((null)) errno 2 (No such file or directory)
[14/Jul/2016:04:34:42 -0400] slapi_ldap_bind - Error: could not perform interactive bind for id [] authentication mechanism [GSSAPI]: error -1 (Can't contact LDAP server)
[14/Jul/2016:04:34:42 -0400] NSMMReplicationPlugin - agmt="cn=meToreplica2.htestrelm.test" (replica2:389): Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) ()
[14/Jul/2016:04:34:42 -0400] slapd_ldap_sasl_interactive_bind - Error: could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -1 (Can't contact LDAP server) ((null)) errno 0 (Success)
[14/Jul/2016:04:34:42 -0400] slapi_ldap_bind - Error: could not perform interactive bind for id [] authentication mechanism [GSSAPI]: error -1 (Can't contact LDAP server)
[14/Jul/2016:04:34:42 -0400] NSMMReplicationPlugin - agmt="cn=meToreplica3.htestrelm.test" (replica3:389): Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) ()
[14/Jul/2016:04:34:44 -0400] slapd_ldap_sasl_interactive_bind - Error: could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -1 (Can't contact LDAP server) ((null)) errno 0 (Success)
[14/Jul/2016:04:34:44 -0400] slapi_ldap_bind - Error: could not perform interactive bind for id [] authentication mechanism [GSSAPI]: error -1 (Can't contact LDAP server)
[14/Jul/2016:04:34:45 -0400] slapd_ldap_sasl_interactive_bind - Error: could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -1 (Can't contact LDAP server) ((null)) errno 0 (Success)
[14/Jul/2016:04:34:46 -0400] slapi_ldap_bind - Error: could not perform interactive bind for id [] authentication mechanism [GSSAPI]: error -1 (Can't contact LDAP server)
[14/Jul/2016:04:34:46 -0400] schema-compat-plugin - warning: no entries set up under ou=sudoers,dc=htestrelm,dc=test
[14/Jul/2016:04:34:46 -0400] schema-compat-plugin - warning: no entries set up under cn=ng, cn=compat,dc=htestrelm,dc=test
[14/Jul/2016:04:34:46 -0400] slapd_ldap_sasl_interactive_bind - Error: could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -1 (Can't contact LDAP server) ((null)) errno 2 (No such file or directory)
[14/Jul/2016:04:34:46 -0400] slapi_ldap_bind - Error: could not perform interactive bind for id [] authentication mechanism [GSSAPI]: error -1 (Can't contact LDAP server)
[14/Jul/2016:04:34:47 -0400] schema-compat-plugin - warning: no entries set up under cn=computers, cn=compat,dc=htestrelm,dc=test
[14/Jul/2016:04:34:47 -0400] schema-compat-plugin - Finished plugin initialization.

Comment 7 Varun Mylaraiah 2016-07-14 17:14:35 UTC
Sorry, I forgot to mention one more step in comment6 "#service sssd restart"

Steps to verify
Step 1: configured ipa with AD  
Step 2: added default_domain_suffix = ad.domain in /etc/sssd/sssd.conf
Step 3: Restart sssd (#service sssd restart)
Step 4: restart ipa server(ipactl restart)

Comment 9 errata-xmlrpc 2016-08-02 18:35:50 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-1540.html