#833 SSSD should handle AD nesting with intermediate groups lacking UNIX attributes
Closed: Fixed None Opened 13 years ago by sgallagh.

Related to https://bugzilla.redhat.com/show_bug.cgi?id=692090

Active Directory users and groups can be individually set with or without UNIX attributes. In the BZ above, there was a configuration where one group contained UNIX attributes and had a member group that did not. This member group had several member users that DID have UNIX attributes.

With nss_ldap, a lookup of the parent group would include the users from the non-UNIX child group. We need to support this as well.


Fields changed

milestone: NEEDS_TRIAGE => SSSD 1.6.0
owner: somebody => jzeleny

Fields changed

patch: => 1
status: new => assigned

Fields changed

patch: 1 => 0

Currently the patch should be solving functionality required, but it has to wait until ticket #799 is closed and patches pushed.

Fixed in:
- master:
- ba33be9
- ace07a7
- 00142ab

- sssd-1-5
    - ca9f55a3366db8d4cc88ee1991c23f6e68c7233d
    - 4f12fec1197d4e2afd4d1d8bec1b5299292f2962
    - 998d6ef7cc8c40b12fb890624b674fd1e407bdc0

milestone: SSSD 1.6.0 => SSSD 1.5.9
resolution: => fixed
status: assigned => closed

Metadata Update from @sgallagh:
- Issue assigned to jzeleny
- Issue set to the milestone: SSSD 1.5.9

7 years ago

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/1875

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Login to comment on this ticket.

Metadata