In the IPA access provider the service name is only compared up to the length of the service name retrieved from LDAP, so if the value from LDAP is 'su' it will match 'su', 'su-l', 'sudo', ... This is not intended and should be fixed.
Fields changed
milestone: NEEDS_TRIAGE => SSSD 1.2
Fixed by ca6aa84e20e445fb04dfce416a8c3a1912b26451
component: SSSD => IPA Provider fixedin: => 1.2.0 resolution: => fixed status: new => closed tests: 0 => 1
rhbz: => 0
Metadata Update from @sbose: - Issue assigned to sbose - Issue set to the milestone: SSSD 1.2.0
SSSD is moving from Pagure to Github. This means that new issues and pull requests will be accepted only in SSSD's github repository.
This issue has been cloned to Github and is available here: - https://github.com/SSSD/sssd/issues/1503
If you want to receive further updates on the issue, please navigate to the github issue and click on subscribe button.
subscribe
Thank you for understanding. We apologize for all inconvenience.