#2235 MAN: Remove misleading memberof example from ldap_access_filter example
Closed: Fixed Opened by jhrozek.

The example in man sssd-ldap uses the memberof attribute. That's fine per se, but many customers apparently think sssd can use the ldap_access_filter for nested groups, even if AD doesn't have transitive memberof attribute as IPA does. This causes a lot of user confusion.

We should change the example in the manpage and add a note that sssd-simple should be used for nested groups.


Fields changed

milestone: NEEDS_TRIAGE => SSSD 1.11.5

Ticket has been cloned to Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1064908

rhbz: => [https://bugzilla.redhat.com/show_bug.cgi?id=1064908 1064908]

Bumping the priority as this patch was requested by downstream.

priority: major => critical

Fields changed

owner: somebody => jhrozek
patch: 0 => 1
status: new => assigned

  • master: 604d46e028ab62f83060fb88bdd3319a31aca2d1
  • sssd-1-11: 1e45bf20032b4d984e02487bb39cb61210063ea9

resolution: => fixed
status: assigned => closed

Metadata Update from @jhrozek:
- Issue assigned to jhrozek
- Issue set to the milestone: SSSD 1.11.5

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/3277

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata