#47825 Broken dereference control with the FreeIPA 4.0 ACIs
Closed: wontfix None Opened 9 years ago by nhosoi.

This bug is created as a clone of upstream ticket:
https://fedorahosted.org/freeipa/ticket/4389

I've been triaging a login error issue mkosek had today and I believe the
problem is actually on the server side. I'm not sure if it's in IPA (due to the
new ACIs maybe) or 389DS.

With the latest F20 IPA + 389DS combination I've been unable to use the
OpenLDAP dereference control:

ldapsearch -Y GSSAPI -h <host> -b fqdn=<fqdn> -E 'deref=managedBy:objectClass'

Normally, what the result should be is a tuple of dereferenced DN and the
requested attribute (objectClass in this case). I'm only seeing the DN, though.


Duplicate of DS 47821.

Metadata Update from @nhosoi:
- Issue set to the milestone: N/A

7 years ago

389-ds-base is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in 389-ds-base's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/389ds/389-ds-base/issues/1156

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata Update from @spichugi:
- Issue close_status updated to: wontfix (was: Duplicate)

3 years ago

Login to comment on this ticket.

Metadata