Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-5049

Detect foreign security principals in AD group members and silently ignore them

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • None
    • Low
    • 1
    • rhel-idm-sssd
    • ssg_idm
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • RHELs: 10.2, 9.8
    • If docs needed, set a value
    • None
    • 57,005

      Description of problem:

      The newly introduced option "ldap_ignore_unreadable_references" defaults to false which makes SSSD not backward compatible (with say RHEL-8).

      If, for example, AD group contains a foreign security principals which belongs to one-way trusted domain, then on RH-9 group enumeration might fail, but on RH-8 it works (these security principals are ignored).

      Hence I suggest we make this option to default to True so that the same configuration works the same way on RHEL-9 as with RHEL-8

              sbose@redhat.com Sumit Bose
              ovalouse Ondrej Valousek (Inactive)
              Sumit Bose Sumit Bose
              Shridhar Gadekar Shridhar Gadekar
              Votes:
              0 Vote for this issue
              Watchers:
              13 Start watching this issue

                Created:
                Updated: