Hide Forgot
This bug is created as a clone of upstream ticket: https://fedorahosted.org/sssd/ticket/931 pam_ldap had a feature called {{{pam_groupdn}}}. The behavior of this option was to check whether the DN of the user logging in existed as a member of the {{{pam_member_attribute}}} multi-valued attribue of this group DN. Our current answer to users attempting to accomplish similar behavior is to recommend that they use the simple access provider with simple_allow_groups to be set. However, this is somewhat limited in that it only allows access based on POSIX groups, where the pam_groupdn feature could use non-POSIX (administrative-only) groups for this evaluation.
Development Management has reviewed and declined this request. You may appeal this decision by reopening this request.