Bug 767724 - Howto handle trusted domains with SfU or other RFC2307 attributes
Summary: Howto handle trusted domains with SfU or other RFC2307 attributes
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: doc-Identity_Management_Guide
Version: 6.3
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: rc
: 6.3
Assignee: Deon Ballard
QA Contact: ecs-bugs
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-12-14 18:35 UTC by Dmitri Pal
Modified: 2012-07-03 02:54 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2012-07-03 02:54:42 UTC
Target Upstream Version:


Attachments (Terms of Use)

Description Dmitri Pal 2011-12-14 18:35:30 UTC
This bug is created as a clone of upstream ticket:
https://fedorahosted.org/freeipa/ticket/1904

Currently we plan to map Windows SIDs to Unix UID algorithmic (ID range for each domain, RID is added to the lowest ID in the range). But how shall we handle trusted domains where RFC2307 like attributes are already available, e.g. with Services for Unix (SfU) or the IdM for Unix in newer AD versions.

On then one hand it would be irritating that a Windows user with a unix uid and gid will have a different uid and gid on a unix host.

On the other hand a trust relationship means to make all users and groups available. And here we will most certainly fail if not all users and groups in a domain have the RFC2307 attributes and we take those form some users and groups and calculate them for the rest.

So I think it would be better to not look at those attributes at all, but we have to underline this strongly in the documentation


Note You need to log in before you can comment on or make changes to this bug.