Red Hat Bugzilla – Bug 1462343
document information on why SSSD does not use host-based security filtering when processing AD GPOs
Last modified: 2018-05-29 04:26:30 EDT
[+] Description of problem: - At the moment, it is not possible to configure GPOs which apply to specific linux hosts without applying the GPO to an entire OU in which the linux host lives in. It should be documented as to why this is not possible at this time so that users can be better informed.
Upstream ticket: https://pagure.io/SSSD/sssd/issue/3444
To verify: Please check if sssd-ad contains a sufficient answer to comment #0.
master: * 6c1661d2f4e860d1b547d6188a4fe2bd564e87cf
Verified against sssd-1.16.0-14.el7.x86_64 Man page contains the following. " NOTE: The current version of SSSD does not support host (computer) entries in the GPO 'Security Filtering' list. Only user and group entries are supported. Host entries in the list have no effect.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHEA-2018:0929