Bug 646781 - id only returns primary group membership
Summary: id only returns primary group membership
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: sssd
Version: rawhide
Hardware: Unspecified
OS: Unspecified
low
medium
Target Milestone: ---
Assignee: Stephen Gallagher
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-10-26 08:05 UTC by Marcus Moeller
Modified: 2011-01-10 21:30 UTC (History)
4 users (show)

Fixed In Version: sssd-1.5.0-1.fc14
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-01-10 21:30:09 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
sssd log while running id (140.36 KB, application/octet-stream)
2010-10-26 13:13 UTC, Marcus Moeller
no flags Details
sssd log without min_uid set (64.49 KB, text/plain)
2010-10-26 14:06 UTC, Marcus Moeller
no flags Details
sssd.conf (3.79 KB, text/plain)
2010-10-26 14:06 UTC, Marcus Moeller
no flags Details

Description Marcus Moeller 2010-10-26 08:05:36 UTC
Description of problem:

With latest sssd (1.4) an 'id $USERNAME' only returns the primary group whilst groups are returned correctly with getent group (enumerate on).

Comment 1 Jakub Hrozek 2010-10-26 09:29:20 UTC
What is the schema you are using? RFC2307 or RFC2307bis?

Would you mind pasting your sanitized config file along with logfiles?

Comment 2 Marcus Moeller 2010-10-26 13:13:02 UTC
Created attachment 455764 [details]
sssd log while running id

Comment 3 Marcus Moeller 2010-10-26 13:13:34 UTC
We are using RFC2307bis

Comment 4 Stephen Gallagher 2010-10-26 13:18:23 UTC
Your users and groups are being filtered out. Please try removing the 'min_id' and 'max_id' options from sssd.conf and then retry your tests.

Also, please include your config file.

Comment 5 Marcus Moeller 2010-10-26 14:06:23 UTC
Created attachment 455775 [details]
sssd log without min_uid set

Comment 6 Marcus Moeller 2010-10-26 14:06:54 UTC
Created attachment 455776 [details]
sssd.conf

Comment 7 Marcus Moeller 2010-10-26 14:07:18 UTC
removing min_uid leads to exactly the same result

Comment 8 Marcus Moeller 2010-10-26 14:08:38 UTC
Tests without min_id result in exactly the same

Comment 9 Stephen Gallagher 2010-10-26 14:18:06 UTC
Ah, reading through that log, I see that the problem is that with entries that contain parentheses in the distinguished name. We're not properly escaping the search filter, so it's failing because it's not parseable.

We are already tracking this issue upstream: https://fedorahosted.org/sssd/ticket/639

Comment 10 Fedora Update System 2010-12-23 18:45:17 UTC
sssd-1.5.0-1.fc14 has been submitted as an update for Fedora 14.
https://admin.fedoraproject.org/updates/sssd-1.5.0-1.fc14

Comment 11 Fedora Update System 2010-12-25 00:22:25 UTC
sssd-1.5.0-1.fc14 has been pushed to the Fedora 14 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing update sssd'.  You can provide feedback for this update here: https://admin.fedoraproject.org/updates/sssd-1.5.0-1.fc14

Comment 12 Fedora Update System 2011-01-10 21:29:49 UTC
sssd-1.5.0-1.fc14 has been pushed to the Fedora 14 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.