Red Hat Bugzilla – Bug 861076
Flip the default value of ldap_initgroups_use_matching_rule_in_chain
Last modified: 2013-06-06 14:35:44 EDT
This bug is created as a clone of upstream ticket: https://fedorahosted.org/sssd/ticket/1535 The matching rule can actually be slower than not using it. It is also only used when ID mapping is not in use, because when ID-mapping we default to using tokenGroups. We should change the default of ldap_initgroups_use_matching_rule_in_chain from true to false and update the manual page accordingly.
Verified with 1.9.2-59. Verified in manpage sssd-ldap And output of beaker automation run: :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: :: [ LOG ] :: idmap_015 bz861076 Flip the default value of ldap_initgroups_use_matching_rule_in_chain :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::: Stopping sssd: [ OK ] Starting sssd: [ OK ] [ OK ] :: [12:49:42] :: Sleeping for 5 seconds :: [ PASS ] :: File '/var/log/sssd/sssd_ADTEST.log' should contain 'Option ldap_initgroups_use_matching_rule_in_chain is FALSE'
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHSA-2013-0508.html