-
Bug
-
Resolution: Done-Errata
-
Minor
-
rhel-8.8.0
-
sssd-2.9.5-1.el9
-
None
-
Low
-
rhel-sst-idm-sssd
-
ssg_idm
-
12
-
14
-
0
-
False
-
-
None
-
Red Hat Enterprise Linux
-
None
-
Pass
-
None
-
None
SSSD maps mail attribute to an account, and allows users to login using e-mail address (value of mail attribute).
This behavior has caused confusion to some customers. Below man page vaguely documents the behavior.
ldap_user_email (string)
<...> If for some reason several users
need to share the same email address then set this option to a
nonexistent attribute name in order to disable user lookup/login by
email.Default: mail
Could this behavior (allowing users to authenticate using e-mail as a substitute of username) be documented more explicitly?
- links to
-
RHBA-2024:131669 sssd bug fix and enhancement update