#2275 nested netgroups do not work in IPA provider
Closed: Fixed None Opened 6 years ago by preichl.

Nested netgroups do not work using IPA id provider

$ getent netgroup test-netgroup
$ getent netgroup child-test-group
child-test-group      (sssd.dev.work,iuser,ipa.work)

But nested netgroups do work when LDAP is used as id provider and ldap_netgroup_search_base points to compat subtree.

$ getent netgroup test-netgroup
test-netgroup         (-,aaaa,ipa.work) (-,admin,ipa.work) (sssd.dev.work,iuser,ipa.work)
$ getent netgroup child-test-group
child-test-group      (sssd.dev.work,iuser,ipa.work)

Fields changed

owner: somebody => preichl
status: new => assigned

Fields changed

description: Nested groups do not work using IPA id provider
{{{
$ getent netgroup test-netgroup
$ getent netgroup child-test-group
child-test-group (sssd.dev.work,iuser,ipa.work)
}}}

But nested groups do work when LDAP is used as id provider and ldap_netgroup_search_base points to compat subtree.
{{{
$ getent netgroup test-netgroup
test-netgroup (-,aaaa,ipa.work) (-,admin,ipa.work) (sssd.dev.work,iuser,ipa.work)
$ getent netgroup child-test-group
child-test-group (sssd.dev.work,iuser,ipa.work)
}}} => Nested netgroups do not work using IPA id provider
{{{
$ getent netgroup test-netgroup
$ getent netgroup child-test-group
child-test-group (sssd.dev.work,iuser,ipa.work)
}}}

But nested netgroups do work when LDAP is used as id provider and ldap_netgroup_search_base points to compat subtree.
{{{
$ getent netgroup test-netgroup
test-netgroup (-,aaaa,ipa.work) (-,admin,ipa.work) (sssd.dev.work,iuser,ipa.work)
$ getent netgroup child-test-group
child-test-group (sssd.dev.work,iuser,ipa.work)
}}}

Fields changed

milestone: NEEDS_TRIAGE => SSSD 1.13 beta
rhbz: => todo

Fields changed

mark: => 0

This bug is getting noticed by users, we should fix it in 1.13

Required for downstream, but not for Beta

milestone: SSSD 1.13 beta => SSSD 1.13
sensitive: => 0

This ticket has a downstream BZ link, bumping priority

priority: major => critical

Fields changed

owner: preichl => pcech
status: assigned => new

Fields changed

status: new => assigned

Fields changed

patch: 0 => 1

resolution: => fixed
status: assigned => closed

Fields changed

milestone: SSSD 1.13.2 => SSSD 1.13.1

Metadata Update from @preichl:
- Issue assigned to pcech
- Issue set to the milestone: SSSD 1.13.1

3 years ago

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/3317

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Login to comment on this ticket.

Metadata