Uploaded image for project: 'Ambari'
  1. Ambari
  2. AMBARI-13767

LDAP - Group Membership not pulled in with FreeIPA/RHELIDM

    XMLWordPrintableJSON

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Critical
    • Resolution: Fixed
    • Affects Version/s: 2.1.2
    • Fix Version/s: 2.2.0
    • Component/s: ambari-server
    • Labels:
      None
    • Environment:

      All OS

      Description

      When troubleshooting why the group members are not being sync'd with FreeIPA, a packet trace helped identify the issue. With ActiveDirectory the user's DN is exposed as an attribute: "distinguishedName", this is not the case inFreeIPA/RHEL IDM (using 389 DS for the directory server implementation). The DN is not an attribute on the user, and cannot be used in a filter like this:

      (&(objectClass=posixaccount)(|(dn=uid=dstreev,cn=users,cn=accounts,dc=hdp,dc=local)(uid=uid=dstreev,cn=users,cn=accounts,dc=hdp,dc=local)))
      

        Attachments

        1. AMBARI-13767_v4.patch
          24 kB
          Oliver Szabo

          Issue Links

            Activity

              People

              • Assignee:
                oleewere Oliver Szabo
                Reporter:
                oleewere Oliver Szabo
              • Votes:
                1 Vote for this issue
                Watchers:
                4 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: