Red Hat Bugzilla – Bug 877126
subdomains code does not save the proper user/group name
Last modified: 2015-09-29 03:11:57 EDT
This bug is created as a clone of upstream ticket: https://fedorahosted.org/sssd/ticket/1629 example group with trusted user in it returned by sssd now: {{{ [root@ipa1 ~]# getent passwd AD2012\\Administrator administrator@ad2012.ssimo.org:*:1707400500:1707400500::/home/ad2012.ssimo.org/administrator: [root@ipa1 ~]# getent group AD2012\\Administrator administrator@ad2012.ssimo.org:*:1707400500: [root@ipa1 ~]# getent group ad_users ad_users:*:1111800003:administrator }}} as you can see the name is not fully qualified. names from groups comes from the memberuid attribute which is populated by the memberof plugin using the 'name' attribute of the object that is member of the group. the subdomains code is using just the short username for the name attribute. We need to use the fully qualified name instead.
[root@ibm-x3500m4-01 ~]# kinit Password for admin@TESTRELM.COM: [root@ibm-x3500m4-01 ~]# ipa trust-find --------------- 1 trust matched --------------- Realm name: adlab.qe Domain NetBIOS name: ADLAB Domain Security Identifier: S-1-5-21-3655990580-1375374850-1633065477 Trust type: Active Directory domain ---------------------------- Number of entries returned 1 ---------------------------- [root@ibm-x3500m4-01 ~]# getent passwd ADLAB\\adtestuser1 adtestuser1@adlab.qe:*:1979001178:1979001178:adtest user1:/home/adlab.qe/adtestuser1: [root@ibm-x3500m4-01 ~]# getent group ADLAB\\adgroup1 adgroup1@adlab.qe:*:1979001150:tuser1@adlab.qe,tuser2@adlab.qe,adtestuser1@adlab.qe [root@ibm-x3500m4-01 ~]# getent group ad_users ad_users:*:520800004:steeve@adlab.qe,adtestuser2@adlab.qe,tuser1@adlab.qe,fuser@adlab.qe,tuser2@adlab.qe,tuser3@adlab.qe,nuser2@adlab.qe,adtestuser1@adlab.qe,nuser1@adlab.qe Verified in version sssd-client-1.9.2-82.el6.x86_64 sssd-1.9.2-82.el6.x86_64 ipa-server-3.0.0-25.el6.x86_64
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHSA-2013-0508.html