#2161 tokenGroups do not work reliable with Global Catalog
Closed: Fixed Opened by sbose.

The tokenGroups attribute only returns the correct group-memberships then the Global Catalog and the user are coming from the same domain. Lookups for users from other domains in the forest may return incomplete or wrong results.


Ticket has been cloned to Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1033096

rhbz: => [https://bugzilla.redhat.com/show_bug.cgi?id=1033096 1033096]

Fields changed

milestone: NEEDS_TRIAGE => SSSD 1.11.3

Fields changed

owner: somebody => sbose
status: new => assigned

Fields changed

patch: 0 => 1

  • master: 87a6f8fca5fb818d11b7702abb47faf2f3f00b79
  • sssd-1-11: cab9dae09da698f926839380a678c7f02485ae66

resolution: => fixed
status: assigned => closed

Fields changed

changelog: => The AD provider is able to resolve group memberships for groups with Global and Universal scope.
The initgroups (get groups for user) operation for users from trusted AD domains was mode reliable by reading the required tokenGroups attribute from LDAP instead of Global Catalog

Metadata Update from @sbose:
- Issue assigned to sbose
- Issue set to the milestone: SSSD 1.11.3

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/3203

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata