Bug 1868387
| Summary: | system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Alexey Tikhonov <atikhono> |
| Component: | sssd | Assignee: | Paweł Poławski <ppolawsk> |
| Status: | CLOSED ERRATA | QA Contact: | sssd-qe <sssd-qe> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 8.2 | CC: | dlavu, grajaiya, jhrozek, lslebodn, mzidek, pbrezina, ppolawsk, sbose, sgoveas, tscherf |
| Target Milestone: | rc | Keywords: | Triaged |
| Target Release: | 8.0 | Flags: | dlavu:
needinfo-
pm-rhel: mirror+ |
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | sync-to-jira | ||
| Fixed In Version: | sssd-2.3.0-9.el8 | Doc Type: | If docs needed, set a value |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2020-11-04 02:05:29 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Comment 1
Alexey Tikhonov
2020-08-12 14:02:26 UTC
Verified against sssd-2.3.0-9.el8.x86_64 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] +-----------------------------------------------------------------------------------------+ 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] Test:[/sssd/rhel83/client/ad_provider/ad_gpo_hbac/root]: [ Pass(14/14): 100% ] 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] +-----------------------------------------------------------------------------------------+ 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] [ PASS ] :: parent domain gpo is disabled 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] [ PASS ] :: parent domain gpo is enforcing 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] [ PASS ] :: parent domain gpo is enforcing with no gpo applied 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] [ PASS ] :: parent domain gpo is permissive 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] [ PASS ] :: parent domain testing domain and ou inheritance 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] [ PASS ] :: parent domain testing gpo mapping 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] [ PASS ] :: parent domain gpo child fails when log is enabled in smb bz1177140 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] [ PASS ] :: parent domain sssd crashes intermittently in GPO code bz1206092 bz1204203 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] [ PASS ] :: parent domain invalid/empty values in GptTmpl.inf bz1316164 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] [ PASS ] :: parent domain gpos code ignores ad_site option 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] [ PASS ] :: parent domain changed default behavior from allow any to deny any 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] [ PASS ] :: parent domain sssd doesn't follow the link order of AD Group Policy Management 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] [ PASS ] :: parent domain Don't ignore host entries in Group Policy security filters 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] [ PASS ] :: parent domain skip GPOs that have groupPolicyContainers unreadable by sssd 2020-09-21T21:39:48 [ci-vm-10-0-154-95.ho] +----------------------------------------------------------------------+ Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (sssd bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2020:4569 |