Document URL: https://access.redhat.com/documentation/en-us/openshift_container_platform/3.9/html-single/installation_and_configuration/#sync-ldap-augmented-active-directory https://docs.openshift.com/container-platform/3.9/install_config/syncing_groups_with_ldap.html#sync-ldap-augmented-active-directory Section Number and Name: 13.5.4. Augmented Active Directory Example 16. LDAP Sync Configuration Using Augmented Active Directory Schema: augmented_active_directory_config.yaml **************************** [...] augmentedActiveDirectory: groupsQuery: baseDN: "ou=groups,dc=example,dc=com" scope: sub derefAliases: never pageSize: 0 groupUIDAttribute: dn 1 groupNameAttributes: [ cn ] 2 usersQuery: baseDN: "ou=users,dc=example,dc=com" scope: sub derefAliases: never pageSize: 0 [...] **************************** Describe the issue: The LDAP Sync example 16 do not have 'filter' entry and hence the group sync fails with error: **************************** oc adm groups sync --sync-config=ldap-sync.yaml --confirm error: validation of LDAP sync config failed: usersQuery.filter: Invalid value: "": invalid query filter: LDAP Result Code 201 "Filter Compile Error": ldap: filter does not start with an '(' See 'oc adm groups sync -h' for help and examples. **************************** Suggestions for improvement: Add 'filter' entry under augmentedActiveDirectory in example 16. Additional information: Similar to example "Example 13.13. LDAP Sync Configuration Using Active Directory Schema: active_directory_config.yaml" under section "13.5.3. Active Directory". ****************************** [...] usersQuery: baseDN: "ou=users,dc=example,dc=com" scope: sub derefAliases: never filter: (objectclass=inetOrgPerson) pageSize: 0 [...] ******************************
Fixes are in PR https://bugzilla.redhat.com/show_bug.cgi?id=1569444
Commit pushed to master at https://github.com/openshift/openshift-docs https://github.com/openshift/openshift-docs/commit/0b90f0fe6c86d1838867cb9e054b7098f1684bc5 Merge pull request #8874 from gaurav-nelson/bug1569444-fixes added filter for LDAP Sync example
I have merged the fixes and chages should be live soon. Thank you Mahesh Taru