Hide Forgot
Description of problem: sss_groupshow <user> fails with error "No such group in local domain. Printing groups only allowed in local domain" Version-Release number of selected component (if applicable): sssd-client-1.14.0-38.el7.x86_64 sssd-dbus-1.14.0-38.el7.x86_64 sssd-common-pac-1.14.0-38.el7.x86_64 python-sss-1.14.0-38.el7.x86_64 python-sss-murmur-1.14.0-36.el7.x86_64 python-sssdconfig-1.14.0-38.el7.noarch sssd-krb5-common-1.14.0-38.el7.x86_64 sssd-krb5-1.14.0-38.el7.x86_64 sssd-proxy-1.14.0-38.el7.x86_64 libsss_autofs-1.14.0-30.el7.x86_64 libsss_idmap-1.14.0-38.el7.x86_64 sssd-common-1.14.0-38.el7.x86_64 sssd-ipa-1.14.0-38.el7.x86_64 libsss_simpleifp-1.14.0-38.el7.x86_64 sssd-1.14.0-38.el7.x86_64 libsss_nss_idmap-1.14.0-30.el7.x86_64 sssd-debuginfo-1.14.0-30.el7.x86_64 sssd-ad-1.14.0-38.el7.x86_64 sssd-tools-1.14.0-38.el7.x86_64 sssd-ldap-1.14.0-38.el7.x86_64 How reproducible: Steps to Reproduce: 1.Configure sssd.conf as below: [domain/LOCAL] id_provider = local debug_level = 0x0080 [sssd] services = nss,pam config_file_version = 2 domains = LOCAL [nss] filter_groups = root filter_users = root 2. Add few groups as shown below: [root@client1 ~]# sss_groupadd Company [root@client1 ~]# sss_groupadd Engineers [root@client1 ~]# sss_groupadd Sales [root@client1 ~]# sss_groupadd Quality_Engineering [root@client1 ~]# sss_groupadd Development_Engineering 3. Add few users as show below: [root@client1 home]# sss_useradd president [root@client1 home]# sss_useradd devdirector [root@client1 home]# sss_useradd salesenguser [root@client1 home]# sss_useradd qeuser [root@client1 home]# sss_useradd devuser1 [root@client1 home]# sss_useradd devuser2 [root@client1 home]# sss_usermod -a Company president [root@client1 home]# sss_usermod -a Engineers devdirector [root@client1 home]# sss_usermod -a Sales salesenguser [root@client1 home]# sss_usermod -a Quality_Engineering qeuser [root@client1 home]# sss_usermod -a Development_Engineering devuser1 [root@client1 home]# sss_usermod -a Development_Engineering devuser2 [root@client1 home]# sss_groupmod -a Company Engineers [root@client1 home]# sss_groupmod -a Company Sales [root@client1 home]# sss_groupmod -a Engineers Quality_Engineering [root@client1 home]# sss_groupmod -a Engineers Development_Engineering 4. Run sss_groupshow <user> [root@client1 home]# sss_groupshow president No such group in local domain. Printing groups only allowed in local domain. Actual results: sss_groupshow <user> fails Expected results: sss_groupshow <user> should succeed. Additional info:
Upstream ticket: https://fedorahosted.org/sssd/ticket/3184
master: * bb14556c1df503314644fc424fbbf95759791db9 * 812bed08943df8bf3fd1ff9eabcaf5bedc635c92
Versions: ======== sssd-krb5-1.14.0-41.el7.x86_64 sssd-common-1.14.0-41.el7.x86_64 python-sss-1.14.0-41.el7.x86_64 python-sss-murmur-1.14.0-36.el7.x86_64 sssd-client-1.14.0-41.el7.x86_64 sssd-ad-1.14.0-41.el7.x86_64 sssd-proxy-1.14.0-41.el7.x86_64 sssd-tools-1.14.0-41.el7.x86_64 libsss_autofs-1.14.0-30.el7.x86_64 python-sssdconfig-1.14.0-41.el7.noarch sssd-common-pac-1.14.0-41.el7.x86_64 sssd-ldap-1.14.0-41.el7.x86_64 libsss_simpleifp-1.14.0-41.el7.x86_64 libsss_nss_idmap-1.14.0-30.el7.x86_64 sssd-debuginfo-1.14.0-30.el7.x86_64 sssd-krb5-common-1.14.0-41.el7.x86_64 sssd-dbus-1.14.0-41.el7.x86_64 libsss_idmap-1.14.0-41.el7.x86_64 sssd-ipa-1.14.0-41.el7.x86_64 sssd-1.14.0-41.el7.x86_64 sssd.conf : [domain/LOCAL] id_provider = local debug_level = 0x0080 [sssd] services = nss,pam config_file_version = 2 domains = LOCAL [nss] filter_groups = root filter_users = root + sss_groupadd Company_1 + sss_groupadd Engineers_1 + sss_groupadd Sales_1 + sss_groupadd Quality_Engineering_1 + sss_groupadd Development_Engineering_1 + sss_useradd president_1 + sss_useradd devdirector_1 + sss_useradd salesenguser_1 + sss_useradd qeuser_1 + sss_useradd devuser_1 + sss_useradd devuser_2 + sss_usermod -a Company_1 president_1 + sss_usermod -a Engineers_1 devdirector_1 + sss_usermod -a Sales_1 salesenguser_1 + sss_usermod -a Quality_Engineering_1 qeuser_1 + sss_usermod -a Development_Engineering_1 devuser_1 + sss_usermod -a Development_Engineering_1 devuser_2 + sss_groupmod -a Company_1 Engineers + sss_groupmod -a Company_1 Sales + sss_groupmod -a Engineers_1 Quality_Engineering_1 + sss_groupmod -a Engineers_1 Development_Engineering_1 + sss_groupshow president_1 Magic Private Group: president_1@local GID number: 1030 Member users: Is a member of: Member groups:
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHEA-2016-2476.html