-
Notifications
You must be signed in to change notification settings - Fork 252
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Resolving groups with memberOf only #7574
Comments
Hi, can you share your current bye, |
Replaced my domain. |
Hi, you have So, either you change
or you have to add
I would recommend the first. Additionally, since
HTH bye, |
The groups itself are not searchable. Only the memberOf attribute is shown. So I tried every of the combination above (even before opening the ticket). Good to know that the problem seems to lie in the configuration of our ldap server and not me... So I guess I can't configure sssd to search |
Hi, one of the reasons you have to read the group object is to get the GID of the group. bye, |
Oh... our ldap is... special. AFAIK we don't have GIDs in our ldap...
Edit: working on a solution to add the GIDs to the ldap |
Hi, do your LDAP user's have a bye, |
Sorry for the delayed answer - thought I already answered you |
I couldn't find a fitting issue or documentation. Hope I'm not overlooking something basic.
Problem is when I do
getent group foo
sssd tries to search for cn=foo in
ou=users,...
.Our ldap doesn't supply the information this way, but using memberOf.
ldap_user_member_of
is set correctly, but I don't know how to force sssd to use this as the base for group mapping.In theory we can find a group foo through a search in
ou=user,dc=...
memberOf=foo,ou=groups,...
If we want to list the groups of a user we can do a search in
ou=users,...
looking for'uid=foobar' +
(using ldapsearch)Is there a way to configure sssd to work like this as well? Again sorry if this is an obvious problem
The text was updated successfully, but these errors were encountered: