#3310 Support delivering non-POSIX users and groups through the IFP and PAM interfaces

Created a month ago by jhrozek
Modified 12 days ago

Many projects depend on SSSD now to support application integration through Apache modules or directly through SSSD's D-Bus interface. And often, the users and groups in the directory have no POSIX attributes. We should support these use-cases, in particular:
- look up users and groups through the D-Bus interface
- look up group membership through the D-Bus interface including membership in non-POSIX groups
- test authentication and access control through PAM

For the record, use case that triggered this ticket is an application using FreeIPA apache modules, i.e. mod_authnz_pam, mod_intercept_form_submit, mod_lookup_identity.

Fields changed

milestone: NEEDS_TRIAGE => SSSD 1.15.2

a month ago

Metadata Update from @jhrozek:
- Issue set to the milestone: SSSD 1.15.2

12 days ago

Metadata Update from @jhrozek:
- Custom field design_review reset
- Custom field mark reset
- Custom field patch reset
- Custom field review reset
- Custom field sensitive reset
- Custom field testsupdated reset
- Issue close_status updated to: None
- Issue set to the milestone: SSSD 1.15.3 (was: SSSD 1.15.2)

Login to comment on this ticket.

enhancement

SSSD

1.15.0

false

false

https://bugzilla.redhat.com/show_bug.cgi?id=1425891

false

false

false

false

cancel