#3712 [RFE] Add possibility to merge SIDs in the same rules across all applicable GPO
Closed: wontfix 6 years ago Opened 6 years ago by mzidek.

When there are more GPOs applicable to the target and they contain the same rules, then the SIDs in these rules (the vaules) are not concatenated, but overridden (while respecting the precedence).

In some cases it would be easier to design the GP in chunks and specify parts of the users/groups for the same rule in different GPOs. We could add option to SSSD that would enable the SID merging (disabled by default).

Pros: Simplifies configuration in some cases; several people requested this in the past
Cons: Non standard behavior (differs from Win clients);

This issue was created to track the discussion about this RFE.


CC @thor

I would like to propose to close this ticket as WONTFIX. We don't want to deviate from what Windows does with respect to GPOs and I'm afraid that this RFE might just confuse people who expect SSSD-AD to behave just like their Windows clients do.

Thomas, thank you very much for your patch, but I don't think we should include it.

It looks like we agree in not fixing this issue, so I'm closing it.

Metadata Update from @jhrozek:
- Issue close_status updated to: wontfix
- Issue status updated to: Closed (was: Open)

6 years ago

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/4724

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Login to comment on this ticket.

Metadata