#2614 id lookup resolves "Domain Local" group and errors appear in domain log
Closed: Fixed None Opened 5 years ago by jhrozek.

Ticket was cloned from Red Hat Bugzilla (product Red Hat Enterprise Linux 6): Bug 1207720

Description of problem:
id lookup resolves "Domain Local" group and errors appear in domain log.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. sssd.conf domain section has:
debug_level = 0x7480
id_provider = ad
access_provider = ad
ad_domain = sssdad.com
krb5_realm = SSSDAD.COM
cache_credentials = True
krb5_store_password_if_offline = True
use_fully_qualified_names = True

2. Add a group "kaugrp1" with group scope "Domain Local". kau1 user is a member
in that group.

3. # id kau1@sssdad_tree.com
uid=295201603(kau1@sssdad_tree.com) gid=295201603(kau1@sssdad_tree.com)

Actual results:
kaugrp1 is shown as a group and following error appears in the domain log:

(Tue Mar 31 20:00:06 2015) [sssd[be[sssdad.com]]] [sdap_save_group] (0x4000):
AD group [kaugrp1@sssdad_tree.com] has type flags 0x80000004.
(Tue Mar 31 20:00:06 2015) [sssd[be[sssdad.com]]] [sdap_save_group] (0x0400):
Filtering AD group [kaugrp1@sssdad_tree.com]
(Tue Mar 31 20:00:06 2015) [sssd[be[sssdad.com]]] [sysdb_set_entry_attr]
(0x0080): ldb_modify failed: [Attribute or value exists](20)[attribute
'gidNumber': value #1 on
'name=kaugrp1@sssdad_tree.com,cn=groups,cn=sssdad_tree.com,cn=sysdb' provided
more than once]
(Tue Mar 31 20:00:06 2015) [sssd[be[sssdad.com]]] [sysdb_store_group] (0x1000):
sysdb_set_group_attr failed.
(Tue Mar 31 20:00:06 2015) [sssd[be[sssdad.com]]] [sysdb_store_group] (0x0400):
Error: 17 (File exists)
(Tue Mar 31 20:00:06 2015) [sssd[be[sssdad.com]]] [sdap_save_group] (0x0080):
Could not store group with GID: [File exists]
(Tue Mar 31 20:00:06 2015) [sssd[be[sssdad.com]]] [sdap_save_group] (0x0080):
Failed to save group [kaugrp1@sssdad_tree.com]: [File exists]

Expected results:
Domain Local group should not be resolved.

Additional info:

