Bug 947561
| Summary: | filter option in fixup-memberof requires more clarification. | |||
|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Najmuddin Chirammal <nc> | |
| Component: | 389-ds-base | Assignee: | Rich Megginson <rmeggins> | |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | IDM QE LIST <seceng-idm-qe-list> | |
| Severity: | medium | Docs Contact: | ||
| Priority: | medium | |||
| Version: | 7.0 | CC: | amsharma, jgalipea, mreynolds, nhosoi, nkinder, sramling, yjog | |
| Target Milestone: | rc | |||
| Target Release: | 7.0 | |||
| Hardware: | All | |||
| OS: | All | |||
| Whiteboard: | ||||
| Fixed In Version: | 389-ds-base-1.3.1.2-1.el7 | Doc Type: | Bug Fix | |
| Doc Text: |
Cause: If a filter is not supplied, the default filter is "objectclass=inetuser".
Consequence: The documentation states that all users(with memberof attributes) should be checked, but in fact only users with a certain objectclass are checked.
Fix: Correct the filter to use the proper objectclasses for retrieving the correct entries.
Result: The fixup-memberof.pl script/task works as described in the documentation.
|
Story Points: | --- | |
| Clone Of: | ||||
| : | 949364 (view as bug list) | Environment: | ||
| Last Closed: | 2014-06-13 11:48:00 UTC | Type: | Bug | |
| Regression: | --- | Mount Type: | --- | |
| Documentation: | --- | CRM: | ||
| Verified Versions: | Category: | --- | ||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
| Cloudforms Team: | --- | Target Upstream Version: | ||
| Embargoed: | ||||
| Bug Depends On: | ||||
| Bug Blocks: | 949364 | |||
|
Description
Najmuddin Chirammal
2013-04-02 18:11:27 UTC
This bug should be used to correct the fixup-memberof.pl usage output and man page. A separate bug has been opened up to make a change to the Red Hat Directory Server documentation. Upstream ticket: https://fedorahosted.org/389/ticket/47315 moving all ON_QA bugs to MODIFIED in order to add them to the errata (can't add bugs in the ON_QA state to an errata). When the errata is created, the bugs should be automatically moved back to ON_QA. Previously the usage/documentation stated that if you don't supply a filter, then "all" the entries will be checked by the memberof plugin. Actually only entries that have "objectclass: inetuser" were checked. This was not complete and could miss entries, so this fix checks for entries that have the objectclass inetadmin as well. So internally the plugin now looks for entries using this filter "(|(objectclass=inetuser)(objectclass=inetadmin))" Executed Steps :: ================== 1. Create a user with objectclass: inetuser and another user with objectclass=inetadmin 2. Add the users to the group. 3. Enable memberof plugin. 4. Run fixup-memberof.pl to add 'memberof' attributes to the users. ldapsearch -xLLL -p 389 -h localhost -D "cn=Directory Manager" -w Secret123 -b "cn=rhgroup3,ou=people,dc=example,dc=com" dn: cn=rhgroup3,ou=People,dc=example,dc=com objectClass: top objectClass: groupofuniquenames objectClass: ntGroup ntGroupDeleteGroup: true cn: rhgroup3 ntUserDomainId: rhgroup3 ntGroupType: -2147483646 ntUniqueId: 3 uniqueMember: uid=amsharma1,ou=people,dc=example,dc=com uniqueMember: cn=ams,ou=people,dc=example,dc=com enabled plugin [root@dhcp201-149 ~]# fixup-memberof.pl -Z slapd-dhcp201-149 -D "cn=Directory Manager" -w Secret123 -b "dc=example,dc=com" Successfully added task entry "cn=memberOf_fixup_2014_1_20_14_50_6, cn=memberOf task, cn=tasks, cn=config" [root@dhcp201-149 ~]# tail -f /var/log/dirsrv/slapd-dhcp201-149/errors [20/Jan/2014:14:50:05 +051800] memberof-plugin - Memberof task starts (arg: (|(objectclass=inetuser)(objectclass=inetadmin))) ... [20/Jan/2014:14:50:05 +051800] memberof-plugin - Memberof task finished (arg: (|(objectclass=inetuser)(objectclass=inetadmin))) ... AND #man fixup-memberof.pl -f filterAn LDAP query filter to use to select the entries within the subtree to update. If there is no filter set, then the memberOf attribute is regenerated for every entry in the subtree that has the objectclass inetuser/inetadmin. (In reply to Amita Sharma from comment #7) > Executed Steps :: > ================== > 1. Create a user with objectclass: inetuser and another user with > objectclass=inetadmin > 2. Add the users to the group. > 3. Enable memberof plugin. > 4. Run fixup-memberof.pl to add 'memberof' attributes to the users. > ldapsearch -xLLL -p 389 -h localhost -D "cn=Directory Manager" -w Secret123 > -b "cn=rhgroup3,ou=people,dc=example,dc=com" > dn: cn=rhgroup3,ou=People,dc=example,dc=com > objectClass: top > objectClass: groupofuniquenames > objectClass: ntGroup > ntGroupDeleteGroup: true > cn: rhgroup3 > ntUserDomainId: rhgroup3 > ntGroupType: -2147483646 > ntUniqueId: 3 > uniqueMember: uid=amsharma1,ou=people,dc=example,dc=com > uniqueMember: cn=ams,ou=people,dc=example,dc=com > > enabled plugin > > [root@dhcp201-149 ~]# fixup-memberof.pl -Z slapd-dhcp201-149 -D > "cn=Directory Manager" -w Secret123 -b "dc=example,dc=com" > Successfully added task entry "cn=memberOf_fixup_2014_1_20_14_50_6, > cn=memberOf task, cn=tasks, cn=config" > > [root@dhcp201-149 ~]# tail -f /var/log/dirsrv/slapd-dhcp201-149/errors > [20/Jan/2014:14:50:05 +051800] memberof-plugin - Memberof task starts (arg: > (|(objectclass=inetuser)(objectclass=inetadmin))) ... > [20/Jan/2014:14:50:05 +051800] memberof-plugin - Memberof task finished > (arg: (|(objectclass=inetuser)(objectclass=inetadmin))) ... > > AND > > #man fixup-memberof.pl > -f filterAn LDAP query filter to use to select the entries within the > subtree to update. If there is no filter set, then the memberOf attribute is > regenerated for every entry in the subtree that has the objectclass > inetuser/inetadmin. This looks correct. Marking bug as VERIFIED plz see above comments. This request was resolved in Red Hat Enterprise Linux 7.0. Contact your manager or support representative in case you have further questions about the request. |