RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Bug 1350309 - External group-membership fix is incompatible with SSSD's default_domain_suffix option.
Summary: External group-membership fix is incompatible with SSSD's default_domain_suff...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: slapi-nis
Version: 7.2
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: rc
: ---
Assignee: Alexander Bokovoy
QA Contact: Kaleem
Marc Muehlfeld
URL:
Whiteboard:
Depends On: 1346735
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-06-27 06:02 UTC by Marcel Kolaja
Modified: 2016-08-02 18:35 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
A previously updated version of slapi-nis introduced incompatibility of the slapi-nis external group-membership with the System Security Services Daemons (SSSD) default_domain_suffix option. As a consequence, the IPA compat-tree got inaccessible because external members of IPA groups could not be resolved during the initialization, and slapi-nis fails to start. A patch has been applied to fix the schema compatibility plug-in to work with SSSD, and slapi-nis is now compatible with the SSSD default_domain_suffix parameter.
Clone Of: 1346735
Environment:
Last Closed: 2016-08-02 18:35:50 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2016:1540 0 normal SHIPPED_LIVE slapi-nis bug fix update 2016-08-02 22:21:32 UTC

Description Marcel Kolaja 2016-06-27 06:02:36 UTC
This bug has been copied from bug #1346735 and has been proposed
to be backported to 7.2 z-stream (EUS).

Comment 6 Varun Mylaraiah 2016-07-14 14:27:22 UTC
Verified
# rpm -qa slapi-nis* ipa-server
ipa-server-4.2.0-15.el7_2.18.x86_64
slapi-nis-0.54-11.el7_2.x86_64

Step 1: configured ipa with AD  
Step 2: added default_domain_suffix = ad.domain in /etc/sssd/sssd.conf
Step 3: restart ipa server(ipactl restart)

Got expected output ('schema-compat-plugin - Finished plugin initialization.') in /var/log/dirsrv/slapd-HTESTRELM-TEST/errors

Log output:
/var/log/dirsrv/slapd-HTESTRELM-TEST/errors

[14/Jul/2016:04:34:41 -0400] schema-compat-plugin - schema-compat-plugin tree scan will start in about 5 seconds!
[14/Jul/2016:04:34:41 -0400] - slapd started.  Listening on All Interfaces port 389 for LDAP requests
[14/Jul/2016:04:34:41 -0400] - Listening on All Interfaces port 636 for LDAPS requests
[14/Jul/2016:04:34:41 -0400] - Listening on /var/run/slapd-HTESTRELM-TEST.socket for LDAPI requests
[14/Jul/2016:04:34:41 -0400] slapd_ldap_sasl_interactive_bind - Error: could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -1 (Can't contact LDAP server) ((null)) errno 2 (No such file or directory)
[14/Jul/2016:04:34:41 -0400] slapi_ldap_bind - Error: could not perform interactive bind for id [] authentication mechanism [GSSAPI]: error -1 (Can't contact LDAP server)
[14/Jul/2016:04:34:41 -0400] NSMMReplicationPlugin - agmt="cn=meToreplica1.htestrelm.test" (replica1:389): Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) ()
[14/Jul/2016:04:34:42 -0400] slapd_ldap_sasl_interactive_bind - Error: could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -1 (Can't contact LDAP server) ((null)) errno 2 (No such file or directory)
[14/Jul/2016:04:34:42 -0400] slapi_ldap_bind - Error: could not perform interactive bind for id [] authentication mechanism [GSSAPI]: error -1 (Can't contact LDAP server)
[14/Jul/2016:04:34:42 -0400] NSMMReplicationPlugin - agmt="cn=meToreplica2.htestrelm.test" (replica2:389): Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) ()
[14/Jul/2016:04:34:42 -0400] slapd_ldap_sasl_interactive_bind - Error: could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -1 (Can't contact LDAP server) ((null)) errno 0 (Success)
[14/Jul/2016:04:34:42 -0400] slapi_ldap_bind - Error: could not perform interactive bind for id [] authentication mechanism [GSSAPI]: error -1 (Can't contact LDAP server)
[14/Jul/2016:04:34:42 -0400] NSMMReplicationPlugin - agmt="cn=meToreplica3.htestrelm.test" (replica3:389): Replication bind with GSSAPI auth failed: LDAP error -1 (Can't contact LDAP server) ()
[14/Jul/2016:04:34:44 -0400] slapd_ldap_sasl_interactive_bind - Error: could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -1 (Can't contact LDAP server) ((null)) errno 0 (Success)
[14/Jul/2016:04:34:44 -0400] slapi_ldap_bind - Error: could not perform interactive bind for id [] authentication mechanism [GSSAPI]: error -1 (Can't contact LDAP server)
[14/Jul/2016:04:34:45 -0400] slapd_ldap_sasl_interactive_bind - Error: could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -1 (Can't contact LDAP server) ((null)) errno 0 (Success)
[14/Jul/2016:04:34:46 -0400] slapi_ldap_bind - Error: could not perform interactive bind for id [] authentication mechanism [GSSAPI]: error -1 (Can't contact LDAP server)
[14/Jul/2016:04:34:46 -0400] schema-compat-plugin - warning: no entries set up under ou=sudoers,dc=htestrelm,dc=test
[14/Jul/2016:04:34:46 -0400] schema-compat-plugin - warning: no entries set up under cn=ng, cn=compat,dc=htestrelm,dc=test
[14/Jul/2016:04:34:46 -0400] slapd_ldap_sasl_interactive_bind - Error: could not perform interactive bind for id [] mech [GSSAPI]: LDAP error -1 (Can't contact LDAP server) ((null)) errno 2 (No such file or directory)
[14/Jul/2016:04:34:46 -0400] slapi_ldap_bind - Error: could not perform interactive bind for id [] authentication mechanism [GSSAPI]: error -1 (Can't contact LDAP server)
[14/Jul/2016:04:34:47 -0400] schema-compat-plugin - warning: no entries set up under cn=computers, cn=compat,dc=htestrelm,dc=test
[14/Jul/2016:04:34:47 -0400] schema-compat-plugin - Finished plugin initialization.

Comment 7 Varun Mylaraiah 2016-07-14 17:14:35 UTC
Sorry, I forgot to mention one more step in comment6 "#service sssd restart"

Steps to verify
Step 1: configured ipa with AD  
Step 2: added default_domain_suffix = ad.domain in /etc/sssd/sssd.conf
Step 3: Restart sssd (#service sssd restart)
Step 4: restart ipa server(ipactl restart)

Comment 9 errata-xmlrpc 2016-08-02 18:35:50 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-1540.html


Note You need to log in before you can comment on or make changes to this bug.