#3764 SSSD searches IPA users in Default Trust View

Created a month ago by abbra
Modified 10 days ago

Default Trust View in FreeIPA is designed to contain only users and groups from trusted domains. It makes zero sense to search overrides for the users from the primary IPA domain in it:

(Sat Jun 23 10:38:36 2018) [sssd[be[xs.ipa.cool]]] [sdap_get_generic_ext_step] (0x0400): calling ldap_search_ext with [(&(objectClass=ipaOverrideAnchor)(ipaAnchorUUID=:IPA:xs.ipa.cool:86f707d6-76c0-11e8-99bc-001a4a62eb77))][cn=Default Trust View,cn=views,cn=accounts,dc=xs,dc=ipa,dc=cool].

Note that it is OK to search users and groups from other IPA domains (when we get to implement IPA-IPA trust) but right now the search for the primary domain user/group overrides is not required and in fact is wrong.

10 days ago

Metadata Update from @jhrozek:
- Issue set to the milestone: SSSD 2.0

Login to comment on this ticket.

cancel