Bug 455092 - Better handling if default group not found
Better handling if default group not found
Product: freeIPA
Classification: Community
Component: ipa-server (Show other bugs)
All Linux
low Severity low
: ---
: ---
Assigned To: Rob Crittenden
Chandrasekar Kannan
Depends On:
Blocks: 453489
  Show dependency treegraph
Reported: 2008-07-11 17:46 EDT by Rob Crittenden
Modified: 2015-01-04 18:33 EST (History)
2 users (show)

See Also:
Fixed In Version: freeipa-2.0.0-1.fc15
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2012-03-27 03:16:11 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
decent error message if default group not found (1.48 KB, patch)
2008-07-21 15:47 EDT, Rob Crittenden
no flags Details | Diff

  None (edit)
Description Rob Crittenden 2008-07-11 17:46:23 EDT
Description of problem:

When adding a user we attempt to add the user to the default user's group.

If the search for this group fails then adding the user will fail as well.

Currently ipa-adduser will fail with:

# ipa-adduser -f Test -l User testuser
* not found

We should at minimum provide a better error message
Comment 1 Simo Sorce 2008-07-12 11:28:17 EDT
Should we instead make ipausers undeletable ?
Comment 2 Rob Crittenden 2008-07-14 08:34:37 EDT
No. There is no need to require that the group of "everyone" be ipausers.

He put in a perfectly legal group. The problem is that the add_user code assumes
the location in the DIT of the group and constructs the DN. What I will probably
do is store the DN of the default group instead, assuming it doesn't cause too
much grief with installation and I can figure out a way to handle both cases.

What I wanted to avoid is a search for the group whenever a user is added.
Comment 3 Rob Crittenden 2008-07-21 15:47:42 EDT
Created attachment 312294 [details]
decent error message if default group not found

The wrong exception was being used to catch the LDAP not found.
Comment 4 Rob Crittenden 2008-07-23 10:14:26 EDT
master: 23fab304e97d4b275037e066ab93c44e0ed8ae96
Comment 5 Jenny Galipeau 2008-11-25 09:38:01 EST
Fix Verified:

Can't delete default group via webgui or ipa-delgroup.  If you delete the group with ldapmodify and try to add a user - you get a descriptive error message.

[root@jennyv3 /]# ipa-adduser jack
First name: Jack
Last name: O'Lantern
The default group for new users, 'test', cannot be found.
[root@jennyv3 /]# ipa-finduser jack
No entries found for jack

Note You need to log in before you can comment on or make changes to this bug.