-
Bug
-
Resolution: Unresolved
-
Normal
-
rhel-9.1.0
-
None
-
Low
-
1
-
rhel-idm-sssd
-
ssg_idm
-
None
-
False
-
False
-
-
None
-
RHELs: 10.2, 9.8
-
None
-
None
-
If docs needed, set a value
-
-
Unspecified
-
None
-
57,005
Description of problem:
The newly introduced option "ldap_ignore_unreadable_references" defaults to false which makes SSSD not backward compatible (with say RHEL-8).
If, for example, AD group contains a foreign security principals which belongs to one-way trusted domain, then on RH-9 group enumeration might fail, but on RH-8 it works (these security principals are ignored).
Hence I suggest we make this option to default to True so that the same configuration works the same way on RHEL-9 as with RHEL-8